Download CSV

Security Event Logs:

Sr. No.Date and TimeSourceEvent IDTask CategoryDescription
12023-06-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22023-06-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32023-06-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42023-06-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
52023-06-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
62023-06-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
72023-06-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
82023-06-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
92023-06-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
102023-06-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
112023-06-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
122023-06-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132023-06-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
142023-06-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152023-06-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
162023-06-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172023-06-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182023-06-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
232023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
262023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
302023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
312023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
322023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
332023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
342023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
352023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
362023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
372023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
382023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
392023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
402023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
412023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
422023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
432023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
442023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
452023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
462023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
472023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
482023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
492023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
502023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
512023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
522023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
532023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
542023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
552023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
562023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
572023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
582023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
592023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
602023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
612023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
622023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
632023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
642023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
652023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
662023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
672023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
682023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
692023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
702023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
712023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
722023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
732023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
742023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
752023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
762023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
772023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
782023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
792023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
802023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
812023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
822023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
832023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
842023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
852023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
862023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
872023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
882023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
892023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
902023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
912023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
922023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
932023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
942023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
952023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
962023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
972023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
982023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
992023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1002023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1012023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1022023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1032023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1042023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1052023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1062023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1072023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1082023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1092023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1102023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1112023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1122023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1132023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1142023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1152023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1162023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1172023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1182023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1192023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1202023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1212023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1222023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1232023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1242023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1252023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1262023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1272023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1282023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1292023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1302023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1312023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1322023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1332023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1342023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1352023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1362023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1372023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1382023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1392023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1402023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1412023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1422023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1432023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1442023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1452023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1462023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1472023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1482023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1492023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1502023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1512023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1522023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1532023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1542023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1552023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1562023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1572023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1582023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1592023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1602023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1612023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1622023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1632023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1642023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1652023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1662023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1672023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1682023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1692023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1702023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1712023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1722023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1732023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1742023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1752023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1762023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1772023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1782023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1792023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1802023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1812023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1822023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1832023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1842023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1852023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1862023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1872023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1882023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1892023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1902023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1912023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1922023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1932023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1942023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1952023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1962023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1972023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1982023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
1992023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2002023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2012023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2022023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2032023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2042023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2052023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2062023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2072023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2082023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2092023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2102023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2112023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2122023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2132023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2142023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2152023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2162023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2172023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2182023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2192023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2202023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2212023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2222023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2232023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2242023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2252023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2262023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2272023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2282023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2292023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2302023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2312023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2322023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2332023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2342023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2352023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2362023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2372023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2382023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2392023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2402023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2412023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2422023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2432023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2442023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2452023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2462023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2472023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2482023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2492023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2502023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2512023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2522023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2532023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2542023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2552023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2562023-06-10 00:09:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
2572023-06-10 00:09:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
2582023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2592023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2602023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2612023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2622023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2632023-06-10 00:09:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
2642023-06-10 00:09:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
2652023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2662023-06-10 00:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
2672023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2682023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2692023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2702023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2712023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2722023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2732023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2742023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2752023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2762023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2772023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2782023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2792023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2802023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2812023-06-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2822023-06-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2832023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2842023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2852023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2862023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2872023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2882023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2892023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2902023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2912023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2922023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2932023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2942023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2952023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2962023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2972023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
2982023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
2992023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3002023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3012023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3022023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3032023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3042023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3052023-06-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3062023-06-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3072023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3082023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3092023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3102023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3112023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3122023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3132023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3142023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3152023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3162023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3172023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3182023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3192023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3202023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3212023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3222023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3232023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3242023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3252023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3262023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3272023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3282023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3292023-06-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3302023-06-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3312023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3322023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3332023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3342023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3352023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3362023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3372023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3382023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3392023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3402023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3412023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3422023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3432023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3442023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3452023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3462023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3472023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3482023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3492023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3502023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3512023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3522023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3532023-06-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3542023-06-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3552023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3562023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3572023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3582023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3592023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3602023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3612023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3622023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3632023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3642023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3652023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3662023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3672023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3682023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3692023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3702023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3712023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3722023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3732023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3742023-06-10 00:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
3752023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3762023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3772023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3782023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3792023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3802023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3812023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3822023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3832023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3842023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3852023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3862023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3872023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3882023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3892023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3902023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3912023-06-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3922023-06-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3932023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3942023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3952023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3962023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3972023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
3982023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
3992023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4002023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4012023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4022023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4032023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4042023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4052023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4062023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4072023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4082023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4092023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4102023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4112023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4122023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4132023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4142023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4152023-06-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4162023-06-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4172023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4182023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4192023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4202023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4212023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4222023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4232023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4242023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4252023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4262023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4272023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4282023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4292023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4302023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4312023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4322023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4332023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4342023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4352023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4362023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4372023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4382023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4392023-06-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4402023-06-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4412023-06-10 00:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
4422023-06-10 00:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
4432023-06-10 00:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
4442023-06-10 00:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
4452023-06-10 00:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
4462023-06-10 00:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
4472023-06-10 00:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
4482023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4492023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4502023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4512023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4522023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4532023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4542023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4552023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4562023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4572023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4582023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4592023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4602023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4612023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4622023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4632023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4642023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4652023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4662023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4672023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4682023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4692023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4702023-06-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4712023-06-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4722023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4732023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4742023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4752023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4762023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4772023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4782023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4792023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4802023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4812023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4822023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4832023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4842023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4852023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4862023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4872023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4882023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4892023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4902023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4912023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4922023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4932023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4942023-06-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4952023-06-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4962023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4972023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
4982023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
4992023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5002023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5012023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5022023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5032023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5042023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5052023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5062023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5072023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5082023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5092023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5102023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5112023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5122023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5132023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5142023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5152023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5162023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5172023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5182023-06-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5192023-06-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5202023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5212023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5222023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5232023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5242023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5252023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5262023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5272023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5282023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5292023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5302023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5312023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5322023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5332023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5342023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5352023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5362023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5372023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5382023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5392023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5402023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5412023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5422023-05-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5432023-05-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5442023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5452023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5462023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5472023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5482023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5492023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5502023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5512023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5522023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5532023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5542023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5552023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5562023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5572023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5582023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5592023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5602023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5612023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5622023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5632023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5642023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5652023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5662023-05-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5672023-05-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5682023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5692023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5702023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5712023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5722023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5732023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5742023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5752023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5762023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5772023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5782023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5792023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5802023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5812023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5822023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5832023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5842023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5852023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5862023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5872023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5882023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5892023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5902023-05-10 23:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
5912023-05-10 23:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
5922023-05-10 23:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
5932023-05-10 23:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
5942023-05-10 23:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
5952023-05-10 23:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
5962023-05-10 23:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
5972023-05-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
5982023-05-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
5992023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6002023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6012023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6022023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6032023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6042023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6052023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6062023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6072023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6082023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6092023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6102023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6112023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6122023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6132023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6142023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6152023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6162023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6172023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6182023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6192023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6202023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6212023-05-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6222023-05-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6232023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6242023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6252023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6262023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6272023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6282023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6292023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6302023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6312023-05-10 23:55:00Microsoft-Windows-Security-Auditing4799Security Group ManagementA security-enabled local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Group:| Security ID: BUILTIN\Administrators| Group Name: Administrators| Group Domain: Builtin||Process Information:| Process ID: 0x37fc| Process Name: C:\Windows\System32\svchost.exe
6322023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6332023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6342023-05-10 23:55:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
6352023-05-10 23:55:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
6362023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6372023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6382023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6392023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6402023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6412023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6422023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6432023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6442023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6452023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6462023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6472023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6482023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6492023-05-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6502023-05-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6512023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6522023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6532023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6542023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6552023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6562023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6572023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6582023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6592023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6602023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6612023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6622023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6632023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6642023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6652023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6662023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6672023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6682023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6692023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6702023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6712023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6722023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6732023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6742023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6752023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6762023-05-10 23:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
6772023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6782023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6792023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6802023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6812023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6822023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6832023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6842023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6852023-05-10 23:54:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
6862023-05-10 23:54:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
6872023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6882023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6892023-05-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6902023-05-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6912023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6922023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6932023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6942023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6952023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6962023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6972023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
6982023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
6992023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7002023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7012023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7022023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7032023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7042023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7052023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7062023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7072023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7082023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7092023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7102023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7112023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7122023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7132023-05-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7142023-05-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7152023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7162023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7172023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7182023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7192023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7202023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7212023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7222023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7232023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7242023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7252023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7262023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7272023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7282023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7292023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7302023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7312023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7322023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7332023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7342023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7352023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7362023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7372023-05-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7382023-05-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7392023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7402023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7412023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7422023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7432023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7442023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7452023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7462023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7472023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7482023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7492023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7502023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7512023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7522023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7532023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7542023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7552023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7562023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7572023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7582023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7592023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7602023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7612023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7622023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7632023-05-10 23:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
7642023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7652023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7662023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7672023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7682023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7692023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7702023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7712023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7722023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7732023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7742023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7752023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7762023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7772023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7782023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7792023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7802023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7812023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7822023-05-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7832023-05-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7842023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7852023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7862023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7872023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7882023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7892023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7902023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7912023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7922023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7932023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7942023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7952023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7962023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7972023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
7982023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
7992023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8002023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8012023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8022023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8032023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8042023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8052023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8062023-05-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8072023-05-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8082023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8092023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8102023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8112023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8122023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8132023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8142023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8152023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8162023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8172023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8182023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8192023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8202023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8212023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8222023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8232023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8242023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8252023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8262023-05-10 23:49:00Microsoft-Windows-Security-Auditing4799Security Group ManagementA security-enabled local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Group:| Security ID: BUILTIN\Administrators| Group Name: Administrators| Group Domain: Builtin||Process Information:| Process ID: 0x5170| Process Name: C:\Windows\System32\svchost.exe
8272023-05-10 23:49:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8282023-05-10 23:49:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8292023-05-10 23:49:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8302023-05-10 23:49:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8312023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8322023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8332023-05-10 23:49:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8342023-05-10 23:49:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8352023-05-10 23:49:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8362023-05-10 23:49:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x4a30| Process Name: C:\Windows\System32\taskhostw.exe
8372023-05-10 23:49:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x4a30| Process Name: C:\Windows\System32\taskhostw.exe
8382023-05-10 23:49:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x4a30| Process Name: C:\Windows\System32\taskhostw.exe
8392023-05-10 23:49:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x4a30| Process Name: C:\Windows\System32\taskhostw.exe
8402023-05-10 23:49:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
8412023-05-10 23:49:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
8422023-05-10 23:49:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
8432023-05-10 23:49:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
8442023-05-10 23:49:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
8452023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8462023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8472023-05-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8482023-05-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8492023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8502023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8512023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8522023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8532023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8542023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8552023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8562023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8572023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8582023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8592023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8602023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8612023-05-10 23:48:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
8622023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8632023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8642023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8652023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8662023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8672023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8682023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8692023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8702023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8712023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8722023-05-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8732023-05-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8742023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8752023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8762023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8772023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8782023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8792023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8802023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
8812023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
8822023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
8832023-05-10 23:47:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
8842023-05-10 23:47:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
8852023-05-10 23:47:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6F68972||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
8862023-05-10 23:47:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6F6A258||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
8872023-05-10 23:47:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6F689C5||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
8882023-05-10 23:47:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6F6A373||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
8892023-05-10 23:47:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6F6A258||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
8902023-05-10 23:47:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6F6A373| Linked Logon ID: 0x6F6A258| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
8912023-05-10 23:47:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6F6A258| Linked Logon ID: 0x6F6A373| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
8922023-05-10 23:47:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
8932023-05-10 23:47:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
8942023-05-10 23:47:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
8952023-05-10 23:47:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
8962023-05-10 23:47:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6F68972||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
8972023-05-10 23:47:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6F689C5| Linked Logon ID: 0x6F68972| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
8982023-05-10 23:47:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6F68972| Linked Logon ID: 0x6F689C5| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
8992023-05-10 23:47:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
9002023-05-10 23:47:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
9012023-05-10 23:47:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
9022023-05-10 23:47:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
9032023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9042023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9052023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9062023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9072023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9082023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9092023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9102023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9112023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9122023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9132023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9142023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9152023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9162023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9172023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9182023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9192023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9202023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9212023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9222023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9232023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9242023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9252023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9262023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9272023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9282023-05-10 23:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9292023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9302023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9312023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9322023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9332023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9342023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9352023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9362023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9372023-05-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9382023-05-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9392023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9402023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9412023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9422023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9432023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9442023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9452023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9462023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9472023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9482023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9492023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9502023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9512023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9522023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9532023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9542023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9552023-05-10 23:46:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
9562023-05-10 23:46:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
9572023-05-10 23:46:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
9582023-05-10 23:46:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
9592023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9602023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9612023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9622023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9632023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9642023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9652023-05-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9662023-05-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9672023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9682023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9692023-05-10 23:45:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x7194| Process Name: C:\Windows\System32\LogonUI.exe
9702023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9712023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9722023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9732023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9742023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9752023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9762023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9772023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9782023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9792023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9802023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9812023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9822023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9832023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9842023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9852023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9862023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9872023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9882023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9892023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9902023-05-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9912023-05-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9922023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9932023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9942023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
9952023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
9962023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9972023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9982023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
9992023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10002023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10012023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10022023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10032023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10042023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10052023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10062023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10072023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10082023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10092023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10102023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10112023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10122023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10132023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10142023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10152023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10162023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10172023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10182023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10192023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10202023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10212023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10222023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10232023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10242023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10252023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10262023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10272023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10282023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10292023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10302023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10312023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10322023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10332023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10342023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10352023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10362023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10372023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10382023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10392023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10402023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10412023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10422023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10432023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10442023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10452023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10462023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10472023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10482023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10492023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10502023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10512023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10522023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10532023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10542023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10552023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10562023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10572023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10582023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10592023-05-10 23:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10602023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10612023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10622023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10632023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10642023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10652023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10662023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10672023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10682023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10692023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10702023-05-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10712023-05-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10722023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10732023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10742023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10752023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10762023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10772023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10782023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10792023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10802023-05-10 23:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10812023-05-10 23:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10822023-05-10 23:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10832023-05-10 23:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10842023-05-10 23:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10852023-05-10 23:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10862023-05-10 23:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
10872023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10882023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10892023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10902023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10912023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10922023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10932023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10942023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10952023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10962023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10972023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
10982023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
10992023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11002023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11012023-05-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11022023-05-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11032023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11042023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11052023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11062023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11072023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11082023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11092023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11102023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11112023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11122023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11132023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11142023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11152023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11162023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11172023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11182023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11192023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11202023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11212023-05-10 23:42:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
11222023-05-10 23:42:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
11232023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11242023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11252023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11262023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11272023-05-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11282023-05-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11292023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11302023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11312023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11322023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11332023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11342023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11352023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11362023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11372023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11382023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11392023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11402023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11412023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11422023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11432023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11442023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11452023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11462023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11472023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11482023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11492023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11502023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11512023-05-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11522023-05-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11532023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11542023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11552023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11562023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11572023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11582023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11592023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11602023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11612023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11622023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11632023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11642023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11652023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11662023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11672023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11682023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11692023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11702023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11712023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11722023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11732023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11742023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11752023-05-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11762023-05-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11772023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11782023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11792023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11802023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11812023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11822023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11832023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11842023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11852023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11862023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11872023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11882023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11892023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11902023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11912023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11922023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11932023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11942023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11952023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11962023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11972023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
11982023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
11992023-05-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12002023-05-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12012023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12022023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12032023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12042023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12052023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12062023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12072023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12082023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12092023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12102023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12112023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12122023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12132023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12142023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12152023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12162023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12172023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12182023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12192023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12202023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12212023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12222023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12232023-05-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12242023-05-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12252023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12262023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12272023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12282023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12292023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12302023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12312023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12322023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12332023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12342023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12352023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12362023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12372023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12382023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12392023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12402023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12412023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12422023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12432023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12442023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12452023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12462023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12472023-05-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12482023-05-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12492023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12502023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12512023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12522023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12532023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12542023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12552023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12562023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12572023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12582023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12592023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12602023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12612023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12622023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12632023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12642023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12652023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12662023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12672023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12682023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12692023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12702023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12712023-05-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12722023-05-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12732023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12742023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12752023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12762023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12772023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12782023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12792023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12802023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12812023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12822023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12832023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12842023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12852023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12862023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12872023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12882023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12892023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12902023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12912023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12922023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12932023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12942023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12952023-05-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12962023-05-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12972023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
12982023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
12992023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13002023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13012023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13022023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13032023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13042023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13052023-05-10 23:34:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
13062023-05-10 23:34:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
13072023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13082023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13092023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13102023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13112023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13122023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13132023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13142023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13152023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13162023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13172023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13182023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13192023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13202023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13212023-05-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13222023-05-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13232023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13242023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13252023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13262023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13272023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13282023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13292023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13302023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13312023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13322023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13332023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13342023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13352023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13362023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13372023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13382023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13392023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13402023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13412023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13422023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13432023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13442023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13452023-05-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13462023-05-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13472023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13482023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13492023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13502023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13512023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13522023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13532023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13542023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13552023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13562023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13572023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13582023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13592023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13602023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13612023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13622023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13632023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13642023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13652023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13662023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13672023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13682023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13692023-05-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13702023-05-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13712023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13722023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13732023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13742023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13752023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13762023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13772023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13782023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13792023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13802023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13812023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13822023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13832023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13842023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13852023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13862023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13872023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13882023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13892023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13902023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13912023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13922023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13932023-05-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13942023-05-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13952023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13962023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13972023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
13982023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
13992023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14002023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14012023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14022023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14032023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14042023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14052023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14062023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14072023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14082023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14092023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14102023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14112023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14122023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14132023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14142023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14152023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14162023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14172023-05-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14182023-05-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14192023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14202023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14212023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14222023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14232023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14242023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14252023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14262023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14272023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14282023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14292023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14302023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14312023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14322023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14332023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14342023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14352023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14362023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14372023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14382023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14392023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14402023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14412023-05-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14422023-05-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14432023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14442023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14452023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14462023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14472023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14482023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14492023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14502023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14512023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14522023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14532023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14542023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14552023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14562023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14572023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14582023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14592023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14602023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14612023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14622023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14632023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14642023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14652023-05-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14662023-05-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14672023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14682023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14692023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14702023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14712023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14722023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14732023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14742023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14752023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14762023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
14772023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14782023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14792023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14802023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14812023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14822023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14832023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14842023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14852023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14862023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14872023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14882023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14892023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14902023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14912023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14922023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14932023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14942023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14952023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14962023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14972023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
14982023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
14992023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
15002023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15012023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15022023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15032023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15042023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15052023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15062023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15072023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15082023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15092023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15102023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15112023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15122023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15132023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15142023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15152023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15162023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15172023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15182023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15192023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15202023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15212023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15222023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15232023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15242023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15252023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15262023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15272023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15282023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15292023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15302023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15312023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15322023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15332023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15342023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15352023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15362023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15372023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15382023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15392023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15402023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15412023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15422023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15432023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15442023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15452023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15462023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15472023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15482023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15492023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15502023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15512023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15522023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15532023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15542023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15552023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15562023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15572023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15582023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15592023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15602023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15612023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15622023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
15632023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
15642023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15652023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15662023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15672023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15682023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15692023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15702023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15712023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15722023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15732023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15742023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15752023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15762023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15772023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15782023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15792023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15802023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15812023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15822023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15832023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15842023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15852023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15862023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15872023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15882023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15892023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15902023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15912023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15922023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15932023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15942023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15952023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15962023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15972023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15982023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
15992023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16002023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16012023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16022023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16032023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16042023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16052023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16062023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16072023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16082023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16092023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16102023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16112023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16122023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16132023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16142023-05-10 23:27:00Microsoft-Windows-Security-Auditing4799Security Group ManagementA security-enabled local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Group:| Security ID: BUILTIN\Administrators| Group Name: Administrators| Group Domain: Builtin||Process Information:| Process ID: 0x7314| Process Name: C:\Windows\System32\svchost.exe
16152023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16162023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16172023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16182023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16192023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16202023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16212023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16222023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16232023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16242023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16252023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16262023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
16272023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
16282023-05-10 23:27:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
16292023-05-10 23:27:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
16302023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16312023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16322023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16332023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16342023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16352023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16362023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16372023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16382023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16392023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16402023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16412023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16422023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16432023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16442023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16452023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16462023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16472023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16482023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16492023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16502023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16512023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16522023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16532023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16542023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16552023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16562023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16572023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16582023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16592023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16602023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16612023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16622023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16632023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16642023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16652023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16662023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16672023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16682023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16692023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16702023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16712023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16722023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16732023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16742023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16752023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16762023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16772023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16782023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16792023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16802023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16812023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16822023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16832023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16842023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16852023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16862023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16872023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16882023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16892023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16902023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16912023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16922023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16932023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16942023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16952023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16962023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
16972023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
16982023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
16992023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17002023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17012023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17022023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17032023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17042023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17052023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17062023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17072023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17082023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17092023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17102023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17112023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17122023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17132023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17142023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17152023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17162023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17172023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17182023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17192023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17202023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17212023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17222023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17232023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17242023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17252023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17262023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17272023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17282023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17292023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17302023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17312023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17322023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17332023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17342023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17352023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17362023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17372023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17382023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17392023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17402023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17412023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17422023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17432023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17442023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17452023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17462023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17472023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17482023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17492023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17502023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17512023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17522023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17532023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17542023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17552023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17562023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17572023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17582023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17592023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17602023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17612023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17622023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17632023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17642023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17652023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17662023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17672023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17682023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17692023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17702023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17712023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17722023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17732023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17742023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17752023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17762023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17772023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17782023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17792023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17802023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17812023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17822023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17832023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17842023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17852023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17862023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17872023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17882023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17892023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17902023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17912023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17922023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17932023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17942023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17952023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17962023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17972023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17982023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
17992023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18002023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18012023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18022023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18032023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18042023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18052023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18062023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18072023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18082023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18092023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18102023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18112023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18122023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18132023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18142023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18152023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18162023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18172023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18182023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18192023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18202023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18212023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18222023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18232023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18242023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18252023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18262023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18272023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18282023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18292023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18302023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18312023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18322023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18332023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18342023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18352023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18362023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18372023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18382023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18392023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18402023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18412023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18422023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18432023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18442023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18452023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18462023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18472023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18482023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18492023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18502023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18512023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18522023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18532023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18542023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18552023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18562023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18572023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18582023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18592023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18602023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18612023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18622023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18632023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18642023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18652023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18662023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18672023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18682023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18692023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18702023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18712023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18722023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18732023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18742023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18752023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18762023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18772023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18782023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18792023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18802023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18812023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
18822023-05-10 23:27:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
18832023-05-10 23:27:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
18842023-05-10 23:27:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6D2E2CC||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
18852023-05-10 23:27:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6D2F04B||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
18862023-05-10 23:27:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6D2E357||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
18872023-05-10 23:27:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6D2F13C||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
18882023-05-10 23:27:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6D2F04B||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
18892023-05-10 23:27:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6D2F13C| Linked Logon ID: 0x6D2F04B| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
18902023-05-10 23:27:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6D2F04B| Linked Logon ID: 0x6D2F13C| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
18912023-05-10 23:27:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
18922023-05-10 23:27:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
18932023-05-10 23:27:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
18942023-05-10 23:27:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
18952023-05-10 23:27:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6D2E2CC||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
18962023-05-10 23:27:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6D2E357| Linked Logon ID: 0x6D2E2CC| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
18972023-05-10 23:27:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6D2E2CC| Linked Logon ID: 0x6D2E357| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
18982023-05-10 23:27:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
18992023-05-10 23:27:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
19002023-05-10 23:27:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
19012023-05-10 23:27:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
19022023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19032023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19042023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19052023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19062023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19072023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19082023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19092023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19102023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19112023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19122023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19132023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19142023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19152023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19162023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19172023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19182023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19192023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19202023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19212023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19222023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19232023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19242023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19252023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19262023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19272023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19282023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19292023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19302023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19312023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19322023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19332023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19342023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19352023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19362023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19372023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19382023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19392023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19402023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19412023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19422023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19432023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19442023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19452023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19462023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19472023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19482023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19492023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19502023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19512023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19522023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19532023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19542023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19552023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19562023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19572023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19582023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19592023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19602023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19612023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19622023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19632023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19642023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19652023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19662023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19672023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19682023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19692023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19702023-05-10 23:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
19712023-05-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19722023-05-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19732023-05-10 23:27:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
19742023-05-10 23:27:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
19752023-05-10 23:23:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
19762023-05-10 23:23:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
19772023-05-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19782023-05-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19792023-05-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19802023-05-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19812023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19822023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19832023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19842023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19852023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19862023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19872023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19882023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19892023-05-10 23:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x2468| Process Name: C:\Windows\System32\LogonUI.exe
19902023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19912023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19922023-05-10 23:22:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
19932023-05-10 23:22:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
19942023-05-10 23:22:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
19952023-05-10 23:22:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
19962023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19972023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
19982023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
19992023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20002023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20012023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20022023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20032023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20042023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20052023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20062023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20072023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20082023-05-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20092023-05-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20102023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20112023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20122023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20132023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20142023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20152023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20162023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20172023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20182023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20192023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20202023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20212023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20222023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20232023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20242023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20252023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20262023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20272023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20282023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20292023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20302023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20312023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20322023-05-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20332023-05-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20342023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20352023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20362023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20372023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20382023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20392023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20402023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20412023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20422023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20432023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20442023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20452023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20462023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20472023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20482023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20492023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20502023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20512023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20522023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20532023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20542023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20552023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20562023-05-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20572023-05-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20582023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20592023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20602023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20612023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20622023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20632023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20642023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20652023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20662023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20672023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20682023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20692023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20702023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20712023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20722023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20732023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20742023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20752023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20762023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20772023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20782023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20792023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20802023-05-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20812023-05-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20822023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20832023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20842023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20852023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20862023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20872023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20882023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20892023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20902023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20912023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20922023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20932023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20942023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20952023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20962023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20972023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
20982023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
20992023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21002023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21012023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21022023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21032023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21042023-05-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21052023-05-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21062023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21072023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21082023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21092023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21102023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21112023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21122023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21132023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21142023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21152023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21162023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21172023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21182023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21192023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21202023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21212023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21222023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21232023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21242023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21252023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21262023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21272023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21282023-05-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21292023-05-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21302023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21312023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21322023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21332023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21342023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21352023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21362023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21372023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21382023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21392023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21402023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21412023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21422023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21432023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21442023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21452023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21462023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21472023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21482023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21492023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21502023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21512023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21522023-05-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21532023-05-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21542023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21552023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21562023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21572023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21582023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21592023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21602023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21612023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21622023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21632023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21642023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21652023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21662023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21672023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21682023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21692023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21702023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21712023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21722023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21732023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21742023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21752023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21762023-05-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21772023-05-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21782023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21792023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21802023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21812023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21822023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21832023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21842023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21852023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21862023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21872023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21882023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21892023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21902023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21912023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21922023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21932023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21942023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21952023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21962023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21972023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
21982023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
21992023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22002023-05-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22012023-05-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22022023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22032023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22042023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22052023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22062023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22072023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22082023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22092023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22102023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22112023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22122023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22132023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22142023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22152023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22162023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22172023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22182023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22192023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22202023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22212023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22222023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22232023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22242023-05-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22252023-05-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22262023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22272023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22282023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22292023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22302023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22312023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22322023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22332023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22342023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22352023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22362023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22372023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22382023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22392023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22402023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22412023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22422023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22432023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22442023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22452023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22462023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22472023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22482023-05-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22492023-05-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22502023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22512023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22522023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22532023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22542023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22552023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22562023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22572023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22582023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22592023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22602023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22612023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22622023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22632023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22642023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22652023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22662023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22672023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22682023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22692023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22702023-05-10 23:11:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
22712023-05-10 23:11:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
22722023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22732023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22742023-05-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22752023-05-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22762023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22772023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22782023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22792023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22802023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22812023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22822023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22832023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22842023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22852023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22862023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22872023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22882023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22892023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22902023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22912023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22922023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22932023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22942023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22952023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22962023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22972023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
22982023-05-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
22992023-05-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23002023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23012023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23022023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23032023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23042023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23052023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23062023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23072023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23082023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23092023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23102023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23112023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23122023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23132023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23142023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23152023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23162023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23172023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23182023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23192023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23202023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23212023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23222023-05-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23232023-05-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23242023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23252023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23262023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23272023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23282023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23292023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23302023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23312023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23322023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23332023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23342023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23352023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23362023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23372023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23382023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23392023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23402023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23412023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23422023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23432023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23442023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23452023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23462023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23472023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23482023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23492023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23502023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23512023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23522023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23532023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23542023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23552023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23562023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23572023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23582023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23592023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23602023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23612023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23622023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23632023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23642023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23652023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23662023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23672023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23682023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23692023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23702023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23712023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23722023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23732023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23742023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23752023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23762023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23772023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23782023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23792023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23802023-05-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
23812023-05-10 23:08:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
23822023-05-10 23:08:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
23832023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23842023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23852023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23862023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23872023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23882023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23892023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23902023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23912023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23922023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23932023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23942023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23952023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23962023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23972023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
23982023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
23992023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24002023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24012023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24022023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24032023-05-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24042023-05-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24052023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24062023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24072023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24082023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24092023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24102023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24112023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24122023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24132023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24142023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24152023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24162023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24172023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24182023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24192023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24202023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24212023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24222023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24232023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24242023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24252023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24262023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24272023-05-10 23:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24282023-05-10 23:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24292023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24302023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24312023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24322023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24332023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24342023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24352023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24362023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24372023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24382023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24392023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24402023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24412023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24422023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24432023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24442023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24452023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24462023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24472023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24482023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24492023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24502023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24512023-05-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24522023-05-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24532023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24542023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24552023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24562023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24572023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24582023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24592023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24602023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24612023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24622023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24632023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24642023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24652023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24662023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24672023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24682023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24692023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24702023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24712023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24722023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24732023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24742023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24752023-05-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24762023-05-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24772023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24782023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24792023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24802023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24812023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24822023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24832023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24842023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24852023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24862023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24872023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24882023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24892023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24902023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24912023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24922023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24932023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24942023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24952023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24962023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24972023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
24982023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
24992023-05-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25002023-05-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25012023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25022023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25032023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25042023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25052023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25062023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25072023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25082023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25092023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25102023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25112023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25122023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25132023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25142023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25152023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25162023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25172023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25182023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25192023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25202023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25212023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25222023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25232023-05-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25242023-05-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25252023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25262023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25272023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25282023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25292023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25302023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25312023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25322023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25332023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25342023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25352023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25362023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25372023-05-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
25382023-05-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
25392023-05-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
25402023-05-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
25412023-05-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
25422023-05-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
25432023-05-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
25442023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25452023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25462023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25472023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25482023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25492023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25502023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25512023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25522023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25532023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25542023-05-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25552023-05-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25562023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25572023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25582023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25592023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25602023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25612023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25622023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25632023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25642023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25652023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25662023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25672023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25682023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25692023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25702023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25712023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25722023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25732023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25742023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25752023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25762023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25772023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25782023-05-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25792023-05-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25802023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25812023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25822023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25832023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25842023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25852023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25862023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25872023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25882023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25892023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25902023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25912023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25922023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25932023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25942023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25952023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25962023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25972023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
25982023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
25992023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26002023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26012023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26022023-05-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26032023-05-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26042023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26052023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26062023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26072023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26082023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26092023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26102023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26112023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26122023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26132023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26142023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26152023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26162023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26172023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26182023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26192023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26202023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26212023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26222023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26232023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26242023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26252023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26262023-05-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26272023-05-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26282023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26292023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26302023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26312023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26322023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26332023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26342023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26352023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26362023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26372023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26382023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26392023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26402023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26412023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26422023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26432023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26442023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26452023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26462023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26472023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26482023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26492023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26502023-05-10 22:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26512023-05-10 22:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26522023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26532023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26542023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26552023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26562023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26572023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26582023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26592023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26602023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26612023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26622023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26632023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26642023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26652023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26662023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26672023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26682023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26692023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26702023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26712023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26722023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26732023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26742023-05-10 22:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26752023-05-10 22:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26762023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26772023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26782023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26792023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26802023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26812023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26822023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26832023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26842023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
26852023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
26862023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26872023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26882023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26892023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26902023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26912023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26922023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26932023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26942023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26952023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26962023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26972023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26982023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
26992023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27002023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27012023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
27022023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
27032023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27042023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27052023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27062023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27072023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27082023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27092023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27102023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27112023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27122023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27132023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27142023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27152023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27162023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27172023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27182023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27192023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27202023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27212023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27222023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27232023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27242023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27252023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27262023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27272023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27282023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27292023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27302023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27312023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27322023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27332023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27342023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27352023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27362023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27372023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27382023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27392023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27402023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27412023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27422023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27432023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27442023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27452023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27462023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27472023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27482023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27492023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27502023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27512023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27522023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27532023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27542023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27552023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27562023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27572023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27582023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27592023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
27602023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
27612023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27622023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27632023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27642023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27652023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27662023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27672023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27682023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27692023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27702023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27712023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27722023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
27732023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
27742023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27752023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27762023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27772023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27782023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27792023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27802023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27812023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27822023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27832023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27842023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27852023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27862023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27872023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27882023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27892023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27902023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27912023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27922023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27932023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27942023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27952023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27962023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27972023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27982023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
27992023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28002023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28012023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28022023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28032023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28042023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28052023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28062023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28072023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28082023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28092023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28102023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28112023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28122023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28132023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28142023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28152023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28162023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28172023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28182023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28192023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28202023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28212023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28222023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28232023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28242023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28252023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28262023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28272023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28282023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28292023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28302023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28312023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28322023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28332023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28342023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28352023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28362023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28372023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28382023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28392023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28402023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28412023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
28422023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
28432023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28442023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28452023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28462023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28472023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28482023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28492023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28502023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28512023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28522023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28532023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28542023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28552023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28562023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28572023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28582023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28592023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28602023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28612023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28622023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28632023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28642023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28652023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28662023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28672023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28682023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28692023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28702023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28712023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28722023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28732023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28742023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28752023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28762023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28772023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28782023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28792023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28802023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28812023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28822023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28832023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28842023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28852023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28862023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28872023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28882023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28892023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28902023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28912023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28922023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28932023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28942023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28952023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28962023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28972023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28982023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
28992023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29002023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29012023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29022023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29032023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29042023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29052023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29062023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29072023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29082023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29092023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29102023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29112023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29122023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29132023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29142023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29152023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29162023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29172023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29182023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29192023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29202023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29212023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29222023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29232023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29242023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29252023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29262023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29272023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29282023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29292023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29302023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29312023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29322023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29332023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29342023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29352023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29362023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29372023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29382023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29392023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29402023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29412023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29422023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29432023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29442023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29452023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29462023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29472023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29482023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29492023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29502023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29512023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29522023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29532023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29542023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
29552023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
29562023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29572023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29582023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29592023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29602023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29612023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29622023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29632023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29642023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29652023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29662023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29672023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29682023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29692023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29702023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29712023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29722023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29732023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29742023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29752023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29762023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29772023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29782023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29792023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29802023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29812023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29822023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29832023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29842023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29852023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29862023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29872023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29882023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29892023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29902023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29912023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29922023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29932023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29942023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29952023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29962023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29972023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29982023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
29992023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30002023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30012023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30022023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30032023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30042023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30052023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30062023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30072023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30082023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30092023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30102023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30112023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30122023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30132023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30142023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30152023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30162023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30172023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30182023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30192023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30202023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30212023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30222023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30232023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30242023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30252023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30262023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30272023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30282023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30292023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30302023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30312023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30322023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30332023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30342023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30352023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30362023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30372023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30382023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30392023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30402023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30412023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30422023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30432023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30442023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30452023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30462023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30472023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30482023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30492023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30502023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30512023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30522023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30532023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30542023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30552023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30562023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30572023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30582023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30592023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30602023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30612023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30622023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30632023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30642023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30652023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30662023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30672023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30682023-05-10 22:56:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6B8B0BD||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
30692023-05-10 22:56:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6B8C2FE||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
30702023-05-10 22:56:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6B8B233||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
30712023-05-10 22:56:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6B8C4A6||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
30722023-05-10 22:56:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6B8C2FE||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
30732023-05-10 22:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6B8C4A6| Linked Logon ID: 0x6B8C2FE| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
30742023-05-10 22:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6B8C2FE| Linked Logon ID: 0x6B8C4A6| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
30752023-05-10 22:56:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
30762023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30772023-05-10 22:56:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
30782023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30792023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30802023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30812023-05-10 22:56:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
30822023-05-10 22:56:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
30832023-05-10 22:56:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6B8B0BD||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
30842023-05-10 22:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6B8B233| Linked Logon ID: 0x6B8B0BD| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
30852023-05-10 22:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6B8B0BD| Linked Logon ID: 0x6B8B233| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
30862023-05-10 22:56:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
30872023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30882023-05-10 22:56:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
30892023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30902023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30912023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30922023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30932023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30942023-05-10 22:56:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
30952023-05-10 22:56:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
30962023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30972023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30982023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
30992023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31002023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31012023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31022023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31032023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31042023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31052023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31062023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31072023-05-10 22:56:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
31082023-05-10 22:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
31092023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31102023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31112023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31122023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31132023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31142023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31152023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31162023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31172023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31182023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31192023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31202023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31212023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31222023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31232023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31242023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31252023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31262023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31272023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31282023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31292023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31302023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31312023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31322023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31332023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31342023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31352023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31362023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31372023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31382023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31392023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31402023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31412023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31422023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31432023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31442023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31452023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31462023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31472023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31482023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31492023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31502023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31512023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31522023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31532023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31542023-05-10 22:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
31552023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31562023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31572023-05-10 22:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31582023-05-10 22:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31592023-05-10 22:56:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
31602023-05-10 22:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
31612023-05-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31622023-05-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31632023-05-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31642023-05-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31652023-05-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31662023-05-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31672023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31682023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31692023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31702023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31712023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31722023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31732023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31742023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31752023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31762023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31772023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31782023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31792023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31802023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31812023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31822023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31832023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31842023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31852023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31862023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31872023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31882023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31892023-05-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31902023-05-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31912023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31922023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31932023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31942023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31952023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31962023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31972023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
31982023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
31992023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32002023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32012023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32022023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32032023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32042023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32052023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32062023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32072023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32082023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32092023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32102023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32112023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32122023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32132023-05-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32142023-05-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32152023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32162023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32172023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32182023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32192023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32202023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32212023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32222023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32232023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32242023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32252023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32262023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32272023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32282023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32292023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32302023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32312023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32322023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32332023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32342023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32352023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32362023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32372023-05-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32382023-05-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32392023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32402023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32412023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32422023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32432023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32442023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32452023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32462023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32472023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32482023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32492023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32502023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32512023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32522023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32532023-05-10 22:38:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
32542023-05-10 22:38:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
32552023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32562023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32572023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32582023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32592023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32602023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32612023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32622023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32632023-05-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32642023-05-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32652023-05-10 22:37:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x77f0| Process Name: C:\Windows\System32\LogonUI.exe
32662023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32672023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32682023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32692023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32702023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32712023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32722023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32732023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32742023-05-10 22:37:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
32752023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32762023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32772023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32782023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32792023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32802023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32812023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32822023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32832023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
32842023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
32852023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32862023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32872023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32882023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32892023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32902023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32912023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32922023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32932023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32942023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32952023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32962023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32972023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32982023-05-10 22:37:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
32992023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
33002023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
33012023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
33022023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
33032023-05-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
33042023-05-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
33052023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
33062023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
33072023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
33082023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
33092023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
33102023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
33112023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33122023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33132023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33142023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33152023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33162023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33172023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33182023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33192023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33202023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33212023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33222023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33232023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33242023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33252023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
33262023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
33272023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33282023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33292023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33302023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33312023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33322023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33332023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33342023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33352023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33362023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33372023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33382023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33392023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33402023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33412023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
33422023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
33432023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33442023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33452023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33462023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33472023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33482023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33492023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33502023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33512023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33522023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33532023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33542023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33552023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33562023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33572023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
33582023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
33592023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
33602023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
33612023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33622023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33632023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33642023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33652023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33662023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33672023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33682023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33692023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33702023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33712023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33722023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33732023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33742023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33752023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
33762023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
33772023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33782023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33792023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33802023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33812023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33822023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33832023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33842023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33852023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33862023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33872023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33882023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33892023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33902023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33912023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33922023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33932023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33942023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33952023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33962023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33972023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33982023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
33992023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34002023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34012023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34022023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34032023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34042023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34052023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34062023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34072023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34082023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34092023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34102023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34112023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34122023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34132023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34142023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34152023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34162023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34172023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34182023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34192023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34202023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34212023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34222023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34232023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34242023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34252023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34262023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34272023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34282023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34292023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34302023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34312023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34322023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34332023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34342023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34352023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34362023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34372023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34382023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34392023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34402023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34412023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34422023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34432023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34442023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34452023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34462023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34472023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
34482023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
34492023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34502023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34512023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34522023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34532023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34542023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34552023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34562023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
34572023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
34582023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34592023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34602023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34612023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34622023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34632023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34642023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34652023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34662023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34672023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34682023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34692023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34702023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34712023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34722023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34732023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34742023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34752023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34762023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34772023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34782023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34792023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34802023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34812023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34822023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34832023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34842023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34852023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34862023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34872023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34882023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34892023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34902023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34912023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34922023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34932023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34942023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34952023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34962023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34972023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34982023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
34992023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35002023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35012023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35022023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35032023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35042023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35052023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35062023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35072023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35082023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
35092023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
35102023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35112023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35122023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35132023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35142023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35152023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35162023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35172023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35182023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35192023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35202023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35212023-05-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
35222023-05-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
35232023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35242023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35252023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35262023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35272023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35282023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35292023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35302023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35312023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35322023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35332023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35342023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35352023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35362023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35372023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35382023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35392023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35402023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35412023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35422023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35432023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35442023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35452023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35462023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35472023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35482023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35492023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35502023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35512023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35522023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35532023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35542023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35552023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35562023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35572023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35582023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35592023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35602023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35612023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35622023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35632023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35642023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35652023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35662023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35672023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35682023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35692023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35702023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35712023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35722023-05-10 22:36:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35732023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35742023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35752023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35762023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35772023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35782023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35792023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35802023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35812023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35822023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35832023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35842023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
35852023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
35862023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35872023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35882023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35892023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35902023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35912023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35922023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35932023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35942023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35952023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35962023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35972023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35982023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
35992023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36002023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36012023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36022023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36032023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36042023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36052023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36062023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36072023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36082023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36092023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36102023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36112023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36122023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36132023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36142023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36152023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36162023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36172023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36182023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36192023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36202023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36212023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36222023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36232023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36242023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36252023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36262023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36272023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36282023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36292023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36302023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36312023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36322023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36332023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36342023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36352023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36362023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36372023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36382023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36392023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36402023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36412023-05-10 22:35:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
36422023-05-10 22:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
36432023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36442023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36452023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36462023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36472023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36482023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36492023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36502023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36512023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36522023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36532023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36542023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36552023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36562023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36572023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36582023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36592023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36602023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36612023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36622023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36632023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36642023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36652023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36662023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36672023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36682023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36692023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36702023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36712023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36722023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36732023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36742023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36752023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36762023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36772023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36782023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36792023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36802023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36812023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36822023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36832023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36842023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36852023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36862023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36872023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36882023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36892023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36902023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36912023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36922023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36932023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36942023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36952023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36962023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36972023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
36982023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
36992023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37002023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37012023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37022023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37032023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37042023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37052023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
37062023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
37072023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37082023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37092023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37102023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37112023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37122023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37132023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37142023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37152023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37162023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37172023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37182023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37192023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37202023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37212023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37222023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37232023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37242023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37252023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37262023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37272023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37282023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37292023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37302023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37312023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37322023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37332023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37342023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37352023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37362023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37372023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37382023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37392023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37402023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37412023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37422023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37432023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37442023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37452023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37462023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37472023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37482023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37492023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37502023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37512023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37522023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37532023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37542023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37552023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37562023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37572023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
37582023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37592023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37602023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37612023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37622023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37632023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37642023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37652023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37662023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37672023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37682023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37692023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37702023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37712023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37722023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37732023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37742023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37752023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37762023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37772023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37782023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37792023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37802023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37812023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37822023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37832023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37842023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37852023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37862023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37872023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37882023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37892023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37902023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37912023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37922023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37932023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37942023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37952023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37962023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37972023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37982023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
37992023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38002023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38012023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38022023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38032023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38042023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38052023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38062023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38072023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38082023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38092023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38102023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38112023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38122023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38132023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38142023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38152023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38162023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38172023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38182023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38192023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38202023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38212023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38222023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38232023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38242023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38252023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38262023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38272023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38282023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38292023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38302023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38312023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38322023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38332023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38342023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38352023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38362023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38372023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38382023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38392023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38402023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38412023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38422023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38432023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38442023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38452023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38462023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38472023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38482023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38492023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38502023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38512023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38522023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38532023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38542023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38552023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38562023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38572023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38582023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38592023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38602023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38612023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38622023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38632023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38642023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38652023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38662023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38672023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38682023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38692023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38702023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38712023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38722023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38732023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38742023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38752023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38762023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38772023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38782023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38792023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38802023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38812023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38822023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38832023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38842023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38852023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38862023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38872023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38882023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38892023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38902023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38912023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38922023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38932023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38942023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38952023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38962023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38972023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38982023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
38992023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39002023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39012023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39022023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39032023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39042023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39052023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39062023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39072023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39082023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39092023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39102023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39112023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39122023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39132023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39142023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39152023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39162023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39172023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39182023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39192023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39202023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39212023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39222023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39232023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39242023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39252023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39262023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39272023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39282023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39292023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39302023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39312023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39322023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39332023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39342023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39352023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39362023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39372023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39382023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39392023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39402023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39412023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39422023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39432023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39442023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39452023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39462023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39472023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39482023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39492023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39502023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39512023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39522023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
39532023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
39542023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39552023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39562023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39572023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39582023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39592023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39602023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
39612023-05-10 22:35:00Microsoft-Windows-Security-Auditing4799Security Group ManagementA security-enabled local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Group:| Security ID: BUILTIN\Administrators| Group Name: Administrators| Group Domain: Builtin||Process Information:| Process ID: 0x6a14| Process Name: C:\Windows\System32\svchost.exe
39622023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39632023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39642023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39652023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39662023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39672023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39682023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39692023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39702023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39712023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39722023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39732023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39742023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39752023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39762023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39772023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39782023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39792023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39802023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39812023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39822023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39832023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39842023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39852023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39862023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39872023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39882023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39892023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39902023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39912023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39922023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39932023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39942023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39952023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39962023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39972023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39982023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
39992023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40002023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40012023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40022023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40032023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40042023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40052023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40062023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40072023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40082023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40092023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40102023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40112023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40122023-05-10 22:35:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6A1CF71||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
40132023-05-10 22:35:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6A1E26B||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
40142023-05-10 22:35:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6A1CFF8||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
40152023-05-10 22:35:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6A1E443||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
40162023-05-10 22:35:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6A1E26B||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
40172023-05-10 22:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6A1E443| Linked Logon ID: 0x6A1E26B| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
40182023-05-10 22:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6A1E26B| Linked Logon ID: 0x6A1E443| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
40192023-05-10 22:35:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
40202023-05-10 22:35:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
40212023-05-10 22:35:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
40222023-05-10 22:35:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
40232023-05-10 22:35:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6A1CF71||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
40242023-05-10 22:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6A1CFF8| Linked Logon ID: 0x6A1CF71| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
40252023-05-10 22:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6A1CF71| Linked Logon ID: 0x6A1CFF8| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
40262023-05-10 22:35:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
40272023-05-10 22:35:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
40282023-05-10 22:35:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
40292023-05-10 22:35:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
40302023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40312023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40322023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40332023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40342023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40352023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40362023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40372023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40382023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40392023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40402023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40412023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40422023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40432023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40442023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40452023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40462023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40472023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40482023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40492023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40502023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40512023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40522023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40532023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40542023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40552023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40562023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40572023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40582023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40592023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40602023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40612023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40622023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40632023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40642023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40652023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40662023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40672023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40682023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40692023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40702023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40712023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40722023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40732023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40742023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40752023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40762023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40772023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40782023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40792023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40802023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40812023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40822023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40832023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40842023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40852023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
40862023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
40872023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
40882023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
40892023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40902023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40912023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40922023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40932023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40942023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
40952023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
40962023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
40972023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
40982023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
40992023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41002023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41012023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41022023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41032023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41042023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41052023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41062023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41072023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41082023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41092023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41102023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41112023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41122023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41132023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41142023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41152023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41162023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41172023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41182023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41192023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41202023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41212023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41222023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41232023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41242023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41252023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41262023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41272023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41282023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41292023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41302023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41312023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41322023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41332023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41342023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41352023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41362023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41372023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41382023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41392023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41402023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41412023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41422023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41432023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41442023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41452023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41462023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41472023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41482023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41492023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41502023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41512023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41522023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41532023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41542023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41552023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41562023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41572023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41582023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41592023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41602023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41612023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41622023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41632023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41642023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41652023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41662023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41672023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41682023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41692023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41702023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41712023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41722023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41732023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41742023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41752023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41762023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41772023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41782023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41792023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41802023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41812023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41822023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41832023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41842023-05-10 22:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
41852023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41862023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41872023-05-10 22:35:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x7660| Process Name: C:\Windows\System32\LogonUI.exe
41882023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41892023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41902023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41912023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41922023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41932023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41942023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41952023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41962023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41972023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
41982023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
41992023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42002023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42012023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42022023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42032023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42042023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42052023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42062023-05-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42072023-05-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42082023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42092023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42102023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42112023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42122023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42132023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42142023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42152023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42162023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42172023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42182023-05-10 22:29:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
42192023-05-10 22:29:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
42202023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42212023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42222023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42232023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42242023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42252023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42262023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42272023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42282023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42292023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42302023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42312023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42322023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42332023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42342023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42352023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42362023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42372023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42382023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42392023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42402023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42412023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42422023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42432023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42442023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42452023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42462023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42472023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42482023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42492023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42502023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42512023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42522023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42532023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42542023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42552023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42562023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42572023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42582023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42592023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42602023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42612023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42622023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42632023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42642023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42652023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42662023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42672023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
42682023-05-10 22:29:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
42692023-05-10 22:29:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
42702023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42712023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
42722023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42732023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42742023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42752023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42762023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42772023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42782023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42792023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42802023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42812023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42822023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42832023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42842023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42852023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42862023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42872023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42882023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42892023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42902023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42912023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42922023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42932023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42942023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42952023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42962023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42972023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42982023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
42992023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43002023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43012023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43022023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43032023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43042023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43052023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43062023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43072023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43082023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43092023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43102023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43112023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43122023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43132023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43142023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43152023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43162023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43172023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43182023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43192023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43202023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43212023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43222023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43232023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43242023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43252023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43262023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43272023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43282023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43292023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43302023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43312023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43322023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43332023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43342023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43352023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43362023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43372023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43382023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43392023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43402023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43412023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43422023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43432023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43442023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43452023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43462023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43472023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43482023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43492023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43502023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43512023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43522023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43532023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43542023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43552023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43562023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43572023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43582023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43592023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43602023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43612023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43622023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43632023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43642023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43652023-05-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
43662023-05-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
43672023-05-10 22:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43682023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43692023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43702023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43712023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43722023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43732023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43742023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43752023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43762023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43772023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43782023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43792023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43802023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43812023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43822023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43832023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43842023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43852023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43862023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43872023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43882023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43892023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43902023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43912023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43922023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43932023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43942023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43952023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43962023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43972023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43982023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
43992023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44002023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44012023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44022023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44032023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44042023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44052023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44062023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44072023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44082023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44092023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44102023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44112023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44122023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44132023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44142023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44152023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44162023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44172023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44182023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44192023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44202023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44212023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44222023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44232023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44242023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44252023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44262023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44272023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44282023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44292023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44302023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44312023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44322023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44332023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44342023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44352023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44362023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44372023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44382023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44392023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44402023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44412023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44422023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44432023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44442023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44452023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44462023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44472023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44482023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44492023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44502023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44512023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44522023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44532023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44542023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44552023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44562023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44572023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44582023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44592023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44602023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44612023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44622023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44632023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44642023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44652023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44662023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44672023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44682023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44692023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44702023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44712023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44722023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44732023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44742023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44752023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44762023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44772023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44782023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44792023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44802023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44812023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44822023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44832023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44842023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44852023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44862023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44872023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44882023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44892023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
44902023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
44912023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
44922023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
44932023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
44942023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
44952023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
44962023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
44972023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
44982023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
44992023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45002023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45012023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45022023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45032023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45042023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45052023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45062023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45072023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45082023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45092023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45102023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45112023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45122023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45132023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45142023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45152023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45162023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45172023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45182023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45192023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45202023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45212023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45222023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45232023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45242023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45252023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45262023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45272023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45282023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45292023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45302023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45312023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45322023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45332023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45342023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45352023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45362023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45372023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45382023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45392023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45402023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45412023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45422023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45432023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45442023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45452023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45462023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45472023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45482023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45492023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45502023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45512023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45522023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45532023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45542023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45552023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45562023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45572023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45582023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45592023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45602023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45612023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45622023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45632023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45642023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45652023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45662023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45672023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45682023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45692023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45702023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45712023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45722023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45732023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45742023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45752023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45762023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45772023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45782023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45792023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45802023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45812023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45822023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45832023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45842023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45852023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45862023-05-10 19:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
45872023-05-10 19:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45882023-05-10 19:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45892023-05-10 19:04:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
45902023-05-10 19:04:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
45912023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45922023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45932023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45942023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45952023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45962023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45972023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
45982023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
45992023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46002023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46012023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46022023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46032023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46042023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46052023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46062023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46072023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46082023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46092023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46102023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46112023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46122023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46132023-05-10 18:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46142023-05-10 18:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46152023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46162023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46172023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46182023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46192023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46202023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46212023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46222023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46232023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46242023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46252023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46262023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46272023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46282023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46292023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46302023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46312023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46322023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46332023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46342023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46352023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46362023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46372023-05-10 18:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46382023-05-10 18:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46392023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46402023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46412023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46422023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46432023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46442023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46452023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46462023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46472023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46482023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46492023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46502023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46512023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46522023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46532023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46542023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46552023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46562023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46572023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46582023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46592023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46602023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46612023-05-10 18:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46622023-05-10 18:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46632023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46642023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46652023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46662023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46672023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46682023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46692023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46702023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46712023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46722023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46732023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46742023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46752023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46762023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46772023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46782023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46792023-05-10 18:25:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
46802023-05-10 18:25:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
46812023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46822023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46832023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46842023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46852023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46862023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46872023-05-10 18:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
46882023-05-10 18:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
46892023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
46902023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
46912023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
46922023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
46932023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
46942023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
46952023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
46962023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
46972023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
46982023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
46992023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47002023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47012023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47022023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47032023-05-10 18:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47042023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
47052023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
47062023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47072023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47082023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47092023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47102023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47112023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47122023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47132023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47142023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47152023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47162023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47172023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47182023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47192023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47202023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47212023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47222023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47232023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47242023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47252023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47262023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47272023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47282023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47292023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47302023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47312023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47322023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47332023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47342023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47352023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47362023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47372023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47382023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47392023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47402023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47412023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47422023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47432023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47442023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47452023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47462023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47472023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47482023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47492023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47502023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47512023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47522023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47532023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47542023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47552023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47562023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47572023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47582023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47592023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47602023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47612023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47622023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47632023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47642023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47652023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47662023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47672023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
47682023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
47692023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47702023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47712023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47722023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47732023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47742023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47752023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47762023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47772023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47782023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47792023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47802023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47812023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47822023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47832023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47842023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47852023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47862023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47872023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47882023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47892023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47902023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47912023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47922023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47932023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47942023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47952023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47962023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47972023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47982023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
47992023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48002023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48012023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48022023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48032023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48042023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48052023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48062023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48072023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48082023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48092023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48102023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48112023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48122023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48132023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48142023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48152023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48162023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48172023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48182023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48192023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48202023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48212023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48222023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48232023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48242023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48252023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48262023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48272023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48282023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48292023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48302023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
48312023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
48322023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48332023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48342023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48352023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48362023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48372023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48382023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48392023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48402023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48412023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48422023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48432023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48442023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48452023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48462023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48472023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48482023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48492023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48502023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48512023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48522023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48532023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48542023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48552023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48562023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48572023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48582023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48592023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48602023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48612023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48622023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48632023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48642023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48652023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48662023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48672023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48682023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48692023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48702023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48712023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48722023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48732023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48742023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48752023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48762023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48772023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48782023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48792023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48802023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48812023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48822023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48832023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48842023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48852023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48862023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48872023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48882023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48892023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48902023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48912023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48922023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48932023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48942023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48952023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48962023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48972023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48982023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
48992023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
49002023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
49012023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49022023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49032023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49042023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49052023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49062023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49072023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49082023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49092023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49102023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49112023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49122023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49132023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49142023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49152023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49162023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49172023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49182023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49192023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49202023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49212023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49222023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49232023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49242023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49252023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49262023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49272023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49282023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49292023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49302023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49312023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49322023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49332023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49342023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49352023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49362023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49372023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49382023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49392023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49402023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49412023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49422023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49432023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49442023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49452023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49462023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49472023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49482023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49492023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49502023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49512023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49522023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49532023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49542023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49552023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49562023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49572023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49582023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49592023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49602023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49612023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49622023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49632023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49642023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49652023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49662023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49672023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49682023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49692023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49702023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49712023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49722023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49732023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49742023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49752023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49762023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49772023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49782023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49792023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49802023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49812023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49822023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49832023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49842023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49852023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49862023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49872023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49882023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49892023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49902023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49912023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49922023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49932023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49942023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49952023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49962023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49972023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49982023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
49992023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50002023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50012023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50022023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50032023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50042023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50052023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50062023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50072023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50082023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50092023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50102023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50112023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50122023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50132023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50142023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50152023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50162023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50172023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50182023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50192023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50202023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50212023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50222023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50232023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50242023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50252023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50262023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50272023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50282023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50292023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50302023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50312023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50322023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50332023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50342023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50352023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50362023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50372023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50382023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50392023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50402023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50412023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50422023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50432023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50442023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50452023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50462023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50472023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50482023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50492023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50502023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50512023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50522023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50532023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50542023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50552023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50562023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50572023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50582023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50592023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50602023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50612023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50622023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50632023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50642023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50652023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50662023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50672023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50682023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
50692023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
50702023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50712023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50722023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50732023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50742023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50752023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50762023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50772023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50782023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50792023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50802023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50812023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50822023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50832023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50842023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50852023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50862023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50872023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50882023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50892023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50902023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50912023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
50922023-05-10 18:24:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
50932023-05-10 18:24:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
50942023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
50952023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
50962023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
50972023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
50982023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
50992023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51002023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51012023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51022023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51032023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51042023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51052023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51062023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51072023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51082023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51092023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51102023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51112023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51122023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51132023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51142023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51152023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51162023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51172023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51182023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51192023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51202023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51212023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51222023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51232023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51242023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51252023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51262023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51272023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51282023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51292023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51302023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51312023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51322023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51332023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51342023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51352023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51362023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51372023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51382023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51392023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51402023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51412023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51422023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51432023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51442023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51452023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51462023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51472023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51482023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51492023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51502023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51512023-05-10 18:24:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
51522023-05-10 18:24:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
51532023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51542023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51552023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51562023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51572023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51582023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51592023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51602023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51612023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51622023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51632023-05-10 18:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51642023-05-10 18:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51652023-05-10 18:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51662023-05-10 17:47:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
51672023-05-10 17:47:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
51682023-05-10 17:47:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x7660| Process Name: C:\Windows\System32\LogonUI.exe
51692023-05-10 17:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51702023-05-10 17:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51712023-05-10 17:47:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
51722023-05-10 17:47:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
51732023-05-10 17:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51742023-05-10 17:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51752023-05-10 17:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51762023-05-10 17:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51772023-05-10 17:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51782023-05-10 17:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51792023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51802023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51812023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51822023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51832023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51842023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51852023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51862023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51872023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51882023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51892023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51902023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51912023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51922023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51932023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51942023-05-10 17:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
51952023-05-10 17:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
51962023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51972023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51982023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
51992023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52002023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52012023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52022023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52032023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52042023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52052023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52062023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52072023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52082023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52092023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52102023-05-10 17:47:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52112023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
52122023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
52132023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52142023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52152023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52162023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52172023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52182023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52192023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52202023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52212023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52222023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52232023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52242023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52252023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52262023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52272023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52282023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
52292023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
52302023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52312023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52322023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52332023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52342023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52352023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52362023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52372023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52382023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52392023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52402023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52412023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52422023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52432023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52442023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52452023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
52462023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
52472023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52482023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52492023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52502023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52512023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52522023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52532023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52542023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52552023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52562023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52572023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52582023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52592023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52602023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52612023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52622023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
52632023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
52642023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52652023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52662023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52672023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52682023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52692023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52702023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52712023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52722023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52732023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52742023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52752023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52762023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52772023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52782023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52792023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
52802023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
52812023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52822023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52832023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52842023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52852023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52862023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52872023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52882023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52892023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52902023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52912023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52922023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52932023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52942023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52952023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52962023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
52972023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
52982023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
52992023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53002023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53012023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53022023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53032023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53042023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53052023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53062023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53072023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53082023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53092023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53102023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53112023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53122023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53132023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
53142023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
53152023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53162023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53172023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53182023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53192023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53202023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53212023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53222023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53232023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53242023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53252023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53262023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53272023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53282023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53292023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53302023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
53312023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
53322023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53332023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53342023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53352023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53362023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53372023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53382023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53392023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53402023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53412023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53422023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53432023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53442023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53452023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53462023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53472023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
53482023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
53492023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53502023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53512023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53522023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53532023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53542023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53552023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53562023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53572023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53582023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53592023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53602023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53612023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53622023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53632023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53642023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
53652023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
53662023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53672023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53682023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53692023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53702023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53712023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53722023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53732023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53742023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53752023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53762023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53772023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53782023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53792023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53802023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53812023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
53822023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
53832023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53842023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53852023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53862023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53872023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53882023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53892023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53902023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53912023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53922023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53932023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53942023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53952023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53962023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53972023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
53982023-05-10 17:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
53992023-05-10 17:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
54002023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54012023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54022023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54032023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54042023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54052023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54062023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54072023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54082023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54092023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54102023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54112023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54122023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54132023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54142023-05-10 17:46:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54152023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
54162023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
54172023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54182023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54192023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54202023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54212023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54222023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54232023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54242023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54252023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54262023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54272023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54282023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54292023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54302023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54312023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54322023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54332023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54342023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54352023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54362023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54372023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54382023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54392023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54402023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54412023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54422023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54432023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54442023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54452023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54462023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
54472023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
54482023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54492023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54502023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54512023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54522023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54532023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54542023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54552023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54562023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54572023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54582023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54592023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54602023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54612023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54622023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54632023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
54642023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
54652023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54662023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54672023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54682023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54692023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54702023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54712023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54722023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54732023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54742023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54752023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54762023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54772023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54782023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54792023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54802023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
54812023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
54822023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54832023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54842023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54852023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54862023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54872023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54882023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54892023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54902023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54912023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54922023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54932023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54942023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54952023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54962023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
54972023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
54982023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
54992023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55002023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55012023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55022023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55032023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55042023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55052023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55062023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55072023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55082023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55092023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55102023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55112023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55122023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55132023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55142023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
55152023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
55162023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55172023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55182023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55192023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55202023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55212023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55222023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55232023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55242023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55252023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55262023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55272023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55282023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55292023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55302023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55312023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
55322023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
55332023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55342023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55352023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55362023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55372023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55382023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55392023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55402023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55412023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55422023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55432023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55442023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55452023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55462023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55472023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55482023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
55492023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
55502023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55512023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55522023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55532023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55542023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55552023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55562023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55572023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55582023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55592023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55602023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55612023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55622023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55632023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55642023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55652023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
55662023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
55672023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55682023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55692023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55702023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55712023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55722023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55732023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55742023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55752023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55762023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55772023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55782023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55792023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55802023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55812023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55822023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
55832023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
55842023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55852023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55862023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55872023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55882023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55892023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55902023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55912023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55922023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55932023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55942023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55952023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55962023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55972023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55982023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
55992023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
56002023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
56012023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56022023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56032023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56042023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56052023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56062023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56072023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56082023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56092023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56102023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56112023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56122023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56132023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56142023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56152023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56162023-05-10 17:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
56172023-05-10 17:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
56182023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56192023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56202023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56212023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56222023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56232023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56242023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56252023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56262023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56272023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56282023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56292023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56302023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56312023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56322023-05-10 17:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56332023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
56342023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
56352023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56362023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56372023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56382023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56392023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56402023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56412023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56422023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56432023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56442023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56452023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56462023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56472023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56482023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56492023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56502023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
56512023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
56522023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56532023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56542023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56552023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56562023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56572023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56582023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56592023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56602023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56612023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56622023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56632023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56642023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56652023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56662023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56672023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
56682023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
56692023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56702023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56712023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56722023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56732023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56742023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56752023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56762023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56772023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56782023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56792023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56802023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56812023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56822023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56832023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56842023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
56852023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
56862023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56872023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56882023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56892023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56902023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56912023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56922023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56932023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56942023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56952023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56962023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56972023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56982023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
56992023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57002023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57012023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
57022023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
57032023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57042023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57052023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57062023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57072023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57082023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57092023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57102023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57112023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57122023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57132023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57142023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57152023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57162023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57172023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57182023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
57192023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
57202023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57212023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57222023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57232023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57242023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57252023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57262023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57272023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57282023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57292023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57302023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57312023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57322023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57332023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57342023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57352023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
57362023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
57372023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57382023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57392023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57402023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57412023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57422023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57432023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57442023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57452023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57462023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57472023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57482023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57492023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57502023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57512023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57522023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
57532023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
57542023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57552023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57562023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57572023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57582023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57592023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57602023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57612023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57622023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57632023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57642023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57652023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57662023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57672023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57682023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57692023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
57702023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
57712023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
57722023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
57732023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57742023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57752023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57762023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57772023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57782023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57792023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57802023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57812023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57822023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57832023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57842023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57852023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57862023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57872023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57882023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
57892023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
57902023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57912023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57922023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57932023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57942023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57952023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57962023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57972023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57982023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
57992023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58002023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58012023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58022023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58032023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58042023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58052023-05-10 17:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
58062023-05-10 17:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
58072023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58082023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58092023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58102023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58112023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58122023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58132023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58142023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58152023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58162023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58172023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58182023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58192023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58202023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58212023-05-10 17:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58222023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
58232023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
58242023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58252023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58262023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58272023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58282023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58292023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58302023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58312023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58322023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58332023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58342023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58352023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58362023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58372023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58382023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58392023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
58402023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
58412023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58422023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58432023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58442023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58452023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58462023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58472023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58482023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58492023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58502023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58512023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58522023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58532023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58542023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58552023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58562023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
58572023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
58582023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58592023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58602023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58612023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58622023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58632023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58642023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58652023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58662023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58672023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58682023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58692023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58702023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58712023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58722023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58732023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
58742023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
58752023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58762023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58772023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58782023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58792023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58802023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58812023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58822023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58832023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58842023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58852023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58862023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58872023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58882023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58892023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58902023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
58912023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
58922023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58932023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58942023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58952023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58962023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58972023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58982023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
58992023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59002023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59012023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59022023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59032023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59042023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59052023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59062023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59072023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
59082023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
59092023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59102023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59112023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59122023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59132023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59142023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59152023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59162023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59172023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59182023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59192023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59202023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59212023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59222023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59232023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59242023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
59252023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
59262023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59272023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59282023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59292023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59302023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59312023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59322023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59332023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59342023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59352023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59362023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59372023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59382023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59392023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59402023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59412023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
59422023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
59432023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59442023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59452023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59462023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59472023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59482023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59492023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59502023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59512023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59522023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59532023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59542023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59552023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59562023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59572023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59582023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
59592023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
59602023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59612023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59622023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59632023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59642023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59652023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59662023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59672023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59682023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59692023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59702023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59712023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59722023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59732023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59742023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59752023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
59762023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
59772023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59782023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59792023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59802023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59812023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59822023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59832023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59842023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59852023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59862023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59872023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59882023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59892023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59902023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59912023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59922023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
59932023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
59942023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59952023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59962023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59972023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59982023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
59992023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60002023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60012023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60022023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60032023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60042023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60052023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60062023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60072023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60082023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60092023-05-10 17:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
60102023-05-10 17:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
60112023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60122023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60132023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60142023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60152023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60162023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60172023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60182023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60192023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60202023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60212023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60222023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60232023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60242023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60252023-05-10 17:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60262023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
60272023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
60282023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60292023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60302023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60312023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60322023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60332023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60342023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60352023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60362023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60372023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60382023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60392023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60402023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60412023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60422023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60432023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
60442023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
60452023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60462023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60472023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60482023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60492023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60502023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60512023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60522023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60532023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60542023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60552023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60562023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60572023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60582023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60592023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60602023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
60612023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
60622023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60632023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60642023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60652023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60662023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60672023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60682023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60692023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60702023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60712023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60722023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60732023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60742023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60752023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60762023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60772023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
60782023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
60792023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60802023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60812023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60822023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60832023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60842023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60852023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60862023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60872023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60882023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60892023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60902023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60912023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60922023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60932023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60942023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
60952023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
60962023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60972023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60982023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
60992023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61002023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61012023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61022023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61032023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61042023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61052023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61062023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61072023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61082023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61092023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61102023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61112023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
61122023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
61132023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61142023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61152023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61162023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61172023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61182023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61192023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61202023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61212023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61222023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61232023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61242023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61252023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61262023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61272023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61282023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
61292023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
61302023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61312023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61322023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61332023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61342023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61352023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61362023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61372023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61382023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61392023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61402023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61412023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61422023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61432023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61442023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61452023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
61462023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
61472023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61482023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61492023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61502023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61512023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61522023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61532023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61542023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61552023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61562023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61572023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61582023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61592023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61602023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61612023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61622023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
61632023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
61642023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61652023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61662023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61672023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61682023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61692023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61702023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61712023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61722023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61732023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61742023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61752023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61762023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61772023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61782023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61792023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
61802023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
61812023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61822023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61832023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61842023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61852023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61862023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61872023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61882023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61892023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61902023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61912023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61922023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61932023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61942023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61952023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61962023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
61972023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
61982023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
61992023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62002023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62012023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62022023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62032023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62042023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62052023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62062023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62072023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62082023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62092023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62102023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62112023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62122023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62132023-05-10 17:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
62142023-05-10 17:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
62152023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62162023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62172023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62182023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62192023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62202023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62212023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62222023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62232023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62242023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62252023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62262023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62272023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62282023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62292023-05-10 17:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62302023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
62312023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
62322023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62332023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62342023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62352023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62362023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62372023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62382023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62392023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62402023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62412023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62422023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62432023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62442023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62452023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62462023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62472023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
62482023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
62492023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62502023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62512023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62522023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62532023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62542023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62552023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62562023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62572023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62582023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62592023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62602023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62612023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62622023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62632023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62642023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
62652023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
62662023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62672023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62682023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62692023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62702023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62712023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62722023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62732023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62742023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62752023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62762023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62772023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62782023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62792023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62802023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62812023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
62822023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
62832023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62842023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62852023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62862023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62872023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62882023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62892023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62902023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62912023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62922023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62932023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62942023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62952023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62962023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62972023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
62982023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
62992023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
63002023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63012023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63022023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63032023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63042023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63052023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63062023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63072023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63082023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63092023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63102023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63112023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63122023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63132023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63142023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63152023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
63162023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
63172023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63182023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63192023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63202023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63212023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63222023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63232023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63242023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63252023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63262023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63272023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63282023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63292023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63302023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63312023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63322023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
63332023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
63342023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63352023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63362023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63372023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63382023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63392023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63402023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63412023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63422023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63432023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63442023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63452023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63462023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63472023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63482023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63492023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
63502023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
63512023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63522023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63532023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63542023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63552023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63562023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63572023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63582023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63592023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63602023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63612023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63622023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63632023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63642023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63652023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63662023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
63672023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
63682023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63692023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63702023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63712023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63722023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63732023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63742023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63752023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63762023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63772023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63782023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63792023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63802023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63812023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63822023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63832023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
63842023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
63852023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63862023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63872023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63882023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63892023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63902023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63912023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63922023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63932023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63942023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63952023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63962023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63972023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63982023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
63992023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64002023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
64012023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
64022023-05-10 17:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
64032023-05-10 17:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
64042023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64052023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64062023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64072023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64082023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64092023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64102023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64112023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64122023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64132023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64142023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64152023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64162023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64172023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64182023-05-10 17:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64192023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
64202023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
64212023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64222023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64232023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64242023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64252023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64262023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64272023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64282023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64292023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64302023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64312023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64322023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64332023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64342023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64352023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64362023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
64372023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
64382023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64392023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64402023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64412023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64422023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64432023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64442023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64452023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64462023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64472023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64482023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64492023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64502023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64512023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64522023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64532023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
64542023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
64552023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64562023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64572023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64582023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64592023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64602023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64612023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64622023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64632023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64642023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64652023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64662023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64672023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64682023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64692023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64702023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
64712023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
64722023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64732023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64742023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64752023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64762023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64772023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64782023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64792023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64802023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64812023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64822023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64832023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64842023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64852023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64862023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64872023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
64882023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
64892023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64902023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64912023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64922023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64932023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64942023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64952023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64962023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64972023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64982023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
64992023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65002023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65012023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65022023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65032023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65042023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
65052023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
65062023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65072023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65082023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65092023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65102023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65112023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65122023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65132023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65142023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65152023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65162023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65172023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65182023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65192023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65202023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65212023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
65222023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
65232023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65242023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65252023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65262023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65272023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65282023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65292023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65302023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65312023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65322023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65332023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65342023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65352023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65362023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65372023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65382023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
65392023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
65402023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65412023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65422023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65432023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65442023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65452023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65462023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65472023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65482023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65492023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65502023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65512023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65522023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65532023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65542023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65552023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
65562023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
65572023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65582023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65592023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65602023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65612023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65622023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65632023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65642023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65652023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65662023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65672023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65682023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65692023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65702023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65712023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65722023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
65732023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
65742023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65752023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65762023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65772023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65782023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65792023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65802023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65812023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65822023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65832023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65842023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65852023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65862023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65872023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65882023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65892023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
65902023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
65912023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65922023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65932023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65942023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65952023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65962023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65972023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65982023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
65992023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66002023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66012023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66022023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66032023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66042023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66052023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66062023-05-10 17:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
66072023-05-10 17:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
66082023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66092023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66102023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66112023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66122023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66132023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66142023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66152023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66162023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66172023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66182023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66192023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66202023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66212023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66222023-05-10 17:40:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66232023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
66242023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
66252023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66262023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66272023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66282023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66292023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66302023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66312023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66322023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66332023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66342023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66352023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66362023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66372023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66382023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66392023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66402023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
66412023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
66422023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66432023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66442023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66452023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66462023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66472023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66482023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66492023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66502023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66512023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66522023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66532023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66542023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66552023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66562023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66572023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
66582023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
66592023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66602023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66612023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66622023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66632023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66642023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66652023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66662023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66672023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66682023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66692023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66702023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66712023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66722023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66732023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66742023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
66752023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
66762023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66772023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66782023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66792023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66802023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66812023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66822023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66832023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66842023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66852023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66862023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66872023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66882023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66892023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66902023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66912023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
66922023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
66932023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66942023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66952023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66962023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66972023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66982023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
66992023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67002023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67012023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67022023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67032023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67042023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67052023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67062023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67072023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67082023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67092023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67102023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67112023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67122023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67132023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67142023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67152023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67162023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67172023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67182023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67192023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67202023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67212023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67222023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67232023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67242023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67252023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67262023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67272023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67282023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67292023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67302023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67312023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67322023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67332023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67342023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67352023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67362023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67372023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67382023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67392023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67402023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67412023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67422023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67432023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67442023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67452023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67462023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67472023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67482023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
67492023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
67502023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67512023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67522023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67532023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67542023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67552023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67562023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67572023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67582023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67592023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67602023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67612023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67622023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67632023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67642023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67652023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67662023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67672023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67682023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67692023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67702023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67712023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67722023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67732023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67742023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67752023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67762023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67772023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67782023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67792023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67802023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67812023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67822023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67832023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67842023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67852023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67862023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67872023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67882023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67892023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67902023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67912023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67922023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67932023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67942023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67952023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67962023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67972023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67982023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
67992023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68002023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68012023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68022023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68032023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68042023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68052023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
68062023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
68072023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68082023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68092023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68102023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68112023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68122023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68132023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68142023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68152023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68162023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68172023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68182023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68192023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68202023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68212023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68222023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68232023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68242023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68252023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68262023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68272023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68282023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68292023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68302023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68312023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68322023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68332023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68342023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68352023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68362023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68372023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68382023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68392023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68402023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68412023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68422023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68432023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68442023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68452023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68462023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68472023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68482023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68492023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68502023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68512023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68522023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68532023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68542023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68552023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68562023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68572023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68582023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68592023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68602023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68612023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68622023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
68632023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
68642023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68652023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68662023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68672023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68682023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68692023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68702023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68712023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68722023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68732023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68742023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68752023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68762023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68772023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68782023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68792023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68802023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68812023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68822023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68832023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68842023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68852023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68862023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68872023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68882023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68892023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68902023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68912023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68922023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68932023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68942023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68952023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68962023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68972023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68982023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
68992023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69002023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69012023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69022023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69032023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69042023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69052023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69062023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69072023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69082023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69092023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69102023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69112023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69122023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69132023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69142023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69152023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69162023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69172023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69182023-05-10 17:39:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
69192023-05-10 17:39:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
69202023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69212023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69222023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69232023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69242023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69252023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69262023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69272023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69282023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69292023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69302023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69312023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69322023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69332023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69342023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69352023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69362023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
69372023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
69382023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69392023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69402023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69412023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69422023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69432023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69442023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69452023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69462023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69472023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69482023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69492023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69502023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69512023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69522023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69532023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69542023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69552023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69562023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69572023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69582023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69592023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69602023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69612023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69622023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69632023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69642023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69652023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69662023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69672023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69682023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69692023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69702023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69712023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69722023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69732023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69742023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69752023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69762023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69772023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69782023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69792023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69802023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69812023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69822023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69832023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69842023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69852023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69862023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69872023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69882023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
69892023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
69902023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69912023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69922023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69932023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69942023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69952023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
69962023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
69972023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69982023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
69992023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70002023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70012023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70022023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70032023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70042023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70052023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70062023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70072023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70082023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70092023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70102023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70112023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70122023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70132023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70142023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70152023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70162023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70172023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70182023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70192023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70202023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70212023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70222023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70232023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70242023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70252023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70262023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70272023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70282023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70292023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70302023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70312023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70322023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70332023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70342023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70352023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70362023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70372023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70382023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70392023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70402023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70412023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70422023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70432023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70442023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70452023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70462023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70472023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70482023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70492023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70502023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70512023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70522023-05-10 17:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
70532023-05-10 17:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
70542023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70552023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70562023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70572023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70582023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70592023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70602023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70612023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70622023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70632023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70642023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70652023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70662023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70672023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70682023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70692023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70702023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70712023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70722023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70732023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70742023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70752023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70762023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70772023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70782023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70792023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70802023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70812023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70822023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70832023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70842023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70852023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70862023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70872023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70882023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70892023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70902023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70912023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70922023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70932023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70942023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70952023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70962023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70972023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70982023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
70992023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71002023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71012023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71022023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71032023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71042023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71052023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71062023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71072023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71082023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71092023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71102023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71112023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71122023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71132023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71142023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71152023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71162023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71172023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71182023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71192023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71202023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71212023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71222023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71232023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71242023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71252023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71262023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71272023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71282023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71292023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71302023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71312023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71322023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71332023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71342023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71352023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71362023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71372023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71382023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71392023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71402023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71412023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71422023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71432023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71442023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71452023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71462023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71472023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71482023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71492023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71502023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71512023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71522023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71532023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71542023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71552023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71562023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71572023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71582023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71592023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71602023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71612023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71622023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71632023-05-10 17:39:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71642023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
71652023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
71662023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71672023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71682023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71692023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71702023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71712023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71722023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71732023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71742023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71752023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71762023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71772023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71782023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71792023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71802023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71812023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71822023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71832023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71842023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71852023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71862023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71872023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71882023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71892023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71902023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71912023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71922023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71932023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71942023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71952023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71962023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71972023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71982023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
71992023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72002023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72012023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72022023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72032023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72042023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72052023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72062023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72072023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72082023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72092023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72102023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72112023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72122023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72132023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72142023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72152023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72162023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72172023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72182023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72192023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72202023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72212023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72222023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72232023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72242023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72252023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72262023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72272023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72282023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72292023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72302023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72312023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72322023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72332023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72342023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72352023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72362023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72372023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72382023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72392023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72402023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72412023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72422023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72432023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72442023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72452023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72462023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72472023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72482023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72492023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72502023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72512023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72522023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72532023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72542023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72552023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72562023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72572023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72582023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72592023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72602023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72612023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72622023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72632023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72642023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72652023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72662023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72672023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72682023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72692023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72702023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72712023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72722023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72732023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72742023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72752023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72762023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72772023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72782023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72792023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72802023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72812023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72822023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
72832023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
72842023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72852023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72862023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72872023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72882023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72892023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72902023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72912023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72922023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72932023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72942023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72952023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72962023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72972023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72982023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
72992023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73002023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73012023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73022023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73032023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73042023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73052023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73062023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73072023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73082023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73092023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73102023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73112023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73122023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73132023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73142023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73152023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73162023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73172023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73182023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73192023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73202023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73212023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73222023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73232023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73242023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73252023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73262023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73272023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73282023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73292023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73302023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73312023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73322023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73332023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73342023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73352023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73362023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73372023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73382023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73392023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73402023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73412023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73422023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73432023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73442023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73452023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73462023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73472023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73482023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73492023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73502023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73512023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73522023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73532023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73542023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73552023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73562023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73572023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73582023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73592023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73602023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73612023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73622023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73632023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73642023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73652023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73662023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73672023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73682023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73692023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73702023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73712023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73722023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73732023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73742023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73752023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73762023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73772023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73782023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73792023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73802023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73812023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73822023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73832023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73842023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73852023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73862023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73872023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73882023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73892023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73902023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73912023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73922023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73932023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73942023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73952023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
73962023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
73972023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73982023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
73992023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74002023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74012023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74022023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74032023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74042023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74052023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74062023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74072023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74082023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74092023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74102023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74112023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74122023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74132023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74142023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74152023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74162023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74172023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74182023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74192023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74202023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74212023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74222023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74232023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74242023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74252023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74262023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74272023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74282023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74292023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74302023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74312023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74322023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74332023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74342023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74352023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74362023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74372023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74382023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74392023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74402023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74412023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74422023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74432023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74442023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74452023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74462023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74472023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74482023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74492023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74502023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74512023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74522023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74532023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74542023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74552023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74562023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74572023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74582023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74592023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74602023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74612023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74622023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74632023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74642023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74652023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74662023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74672023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74682023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74692023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74702023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74712023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74722023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74732023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74742023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74752023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74762023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74772023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74782023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74792023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74802023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74812023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74822023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74832023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74842023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74852023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74862023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74872023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74882023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74892023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74902023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74912023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74922023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74932023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74942023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74952023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74962023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74972023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74982023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
74992023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75002023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75012023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75022023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75032023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75042023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75052023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75062023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75072023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75082023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75092023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75102023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75112023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75122023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75132023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75142023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75152023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75162023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75172023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75182023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75192023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75202023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75212023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75222023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75232023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75242023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75252023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75262023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75272023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75282023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75292023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75302023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75312023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75322023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75332023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75342023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75352023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75362023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75372023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75382023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75392023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75402023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75412023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75422023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75432023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75442023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75452023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75462023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75472023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75482023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75492023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75502023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75512023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75522023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75532023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75542023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75552023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75562023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75572023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75582023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
75592023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75602023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75612023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75622023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75632023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75642023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75652023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75662023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75672023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75682023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75692023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
75702023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
75712023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75722023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75732023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75742023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75752023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75762023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75772023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75782023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75792023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75802023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75812023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75822023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75832023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75842023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75852023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75862023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75872023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75882023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75892023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75902023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75912023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75922023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75932023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75942023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75952023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75962023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75972023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75982023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
75992023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76002023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76012023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76022023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76032023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76042023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76052023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76062023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76072023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76082023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76092023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76102023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76112023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76122023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76132023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76142023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76152023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76162023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76172023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76182023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76192023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76202023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76212023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76222023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76232023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76242023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76252023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76262023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76272023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76282023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76292023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76302023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76312023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76322023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76332023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76342023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76352023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76362023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76372023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76382023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76392023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76402023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76412023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76422023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76432023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76442023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76452023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76462023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76472023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76482023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76492023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76502023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76512023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76522023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76532023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76542023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76552023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76562023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76572023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76582023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76592023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76602023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76612023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76622023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76632023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76642023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76652023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76662023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76672023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76682023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76692023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76702023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76712023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76722023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76732023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76742023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76752023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76762023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76772023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76782023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76792023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76802023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76812023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76822023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76832023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76842023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76852023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76862023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76872023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76882023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
76892023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76902023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76912023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76922023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76932023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76942023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76952023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76962023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76972023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76982023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
76992023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77002023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77012023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77022023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77032023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77042023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77052023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
77062023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
77072023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
77082023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
77092023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77102023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77112023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77122023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77132023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77142023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77152023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77162023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77172023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77182023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77192023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77202023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77212023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77222023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77232023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77242023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77252023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77262023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77272023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77282023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77292023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77302023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77312023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77322023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77332023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77342023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77352023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77362023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77372023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77382023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77392023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77402023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77412023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77422023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77432023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77442023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77452023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77462023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77472023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77482023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77492023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77502023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77512023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77522023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77532023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77542023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77552023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77562023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77572023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77582023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77592023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77602023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77612023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77622023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77632023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77642023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77652023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77662023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77672023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77682023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77692023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77702023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77712023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77722023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77732023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77742023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77752023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77762023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77772023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77782023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77792023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77802023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77812023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77822023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77832023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77842023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77852023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77862023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77872023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77882023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77892023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77902023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77912023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77922023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77932023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77942023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77952023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77962023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77972023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77982023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
77992023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78002023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78012023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78022023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78032023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78042023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78052023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78062023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78072023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78082023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78092023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78102023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78112023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78122023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78132023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78142023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78152023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78162023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78172023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78182023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78192023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78202023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78212023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78222023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78232023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78242023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78252023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78262023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78272023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78282023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78292023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78302023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78312023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78322023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78332023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78342023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78352023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78362023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78372023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78382023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78392023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78402023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78412023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78422023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78432023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78442023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78452023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78462023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78472023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78482023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78492023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78502023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78512023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78522023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78532023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78542023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78552023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78562023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78572023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78582023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78592023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78602023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78612023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78622023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78632023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78642023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78652023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78662023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78672023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78682023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78692023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78702023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
78712023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
78722023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78732023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78742023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78752023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78762023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78772023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78782023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78792023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78802023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78812023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78822023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78832023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78842023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78852023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78862023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78872023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78882023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78892023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78902023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78912023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78922023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78932023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78942023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78952023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78962023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78972023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78982023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
78992023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79002023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79012023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79022023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79032023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79042023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79052023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79062023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79072023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79082023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79092023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79102023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79112023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79122023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79132023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79142023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79152023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79162023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79172023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79182023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79192023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79202023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79212023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79222023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79232023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79242023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79252023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79262023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79272023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79282023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79292023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79302023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79312023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79322023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79332023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79342023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79352023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79362023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79372023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79382023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79392023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79402023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79412023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79422023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79432023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79442023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79452023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79462023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79472023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79482023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79492023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79502023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79512023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79522023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79532023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79542023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79552023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79562023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79572023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79582023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79592023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79602023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79612023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79622023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79632023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79642023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79652023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79662023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79672023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79682023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79692023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79702023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79712023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79722023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79732023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79742023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79752023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79762023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79772023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79782023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79792023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79802023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79812023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
79822023-05-10 17:38:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x67730C7||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
79832023-05-10 17:38:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x677287C||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
79842023-05-10 17:38:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6773282||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
79852023-05-10 17:38:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x6772912||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
79862023-05-10 17:38:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x67730C7||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
79872023-05-10 17:38:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6773282| Linked Logon ID: 0x67730C7| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
79882023-05-10 17:38:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x67730C7| Linked Logon ID: 0x6773282| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
79892023-05-10 17:38:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
79902023-05-10 17:38:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
79912023-05-10 17:38:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
79922023-05-10 17:38:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
79932023-05-10 17:38:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x677287C||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
79942023-05-10 17:38:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x6772912| Linked Logon ID: 0x677287C| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
79952023-05-10 17:38:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x677287C| Linked Logon ID: 0x6772912| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
79962023-05-10 17:38:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
79972023-05-10 17:38:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
79982023-05-10 17:38:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
79992023-05-10 17:38:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
80002023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80012023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80022023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80032023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80042023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80052023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80062023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80072023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80082023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80092023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80102023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80112023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80122023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80132023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80142023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80152023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80162023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80172023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80182023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80192023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80202023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80212023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80222023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80232023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80242023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80252023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80262023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80272023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80282023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80292023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80302023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80312023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80322023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80332023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80342023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80352023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80362023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80372023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80382023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80392023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80402023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80412023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80422023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80432023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80442023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80452023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80462023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80472023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80482023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80492023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80502023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80512023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80522023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80532023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80542023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80552023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80562023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80572023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80582023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80592023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80602023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80612023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80622023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80632023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80642023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80652023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80662023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
80672023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
80682023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80692023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
80702023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80712023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80722023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
80732023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80742023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80752023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80762023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
80772023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
80782023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
80792023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
80802023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80812023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80822023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80832023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80842023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80852023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80862023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
80872023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
80882023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
80892023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
80902023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80912023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80922023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80932023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80942023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
80952023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80962023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
80972023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80982023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
80992023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81002023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81012023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81022023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81032023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
81042023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
81052023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
81062023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
81072023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
81082023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
81092023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81102023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81112023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81122023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81132023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81142023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81152023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81162023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
81172023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
81182023-05-10 17:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
81192023-05-10 17:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
81202023-05-10 17:38:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
81212023-05-10 17:38:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
81222023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81232023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81242023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81252023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81262023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81272023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81282023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81292023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81302023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81312023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81322023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81332023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81342023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81352023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81362023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81372023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81382023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81392023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81402023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81412023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81422023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81432023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81442023-05-10 17:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81452023-05-10 16:35:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x63c4| Process Name: C:\Windows\System32\LogonUI.exe
81462023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81472023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81482023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81492023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81502023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81512023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81522023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81532023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81542023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81552023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81562023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81572023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81582023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81592023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81602023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81612023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81622023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81632023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81642023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81652023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81662023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81672023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81682023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81692023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81702023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81712023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81722023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81732023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81742023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81752023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81762023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81772023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81782023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81792023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81802023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81812023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81822023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81832023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81842023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81852023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81862023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81872023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81882023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81892023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81902023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81912023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81922023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81932023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81942023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81952023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81962023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81972023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81982023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
81992023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82002023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82012023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82022023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82032023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82042023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82052023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82062023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82072023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82082023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82092023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82102023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82112023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82122023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82132023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82142023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82152023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82162023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82172023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82182023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82192023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82202023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82212023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82222023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82232023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82242023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82252023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82262023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82272023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82282023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82292023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82302023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82312023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82322023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82332023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82342023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82352023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82362023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82372023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82382023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82392023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82402023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82412023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82422023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82432023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82442023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82452023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82462023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82472023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82482023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82492023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82502023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82512023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82522023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82532023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82542023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82552023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82562023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82572023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82582023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82592023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82602023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82612023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82622023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82632023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82642023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82652023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82662023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82672023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82682023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82692023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82702023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82712023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82722023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82732023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82742023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82752023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82762023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82772023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82782023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82792023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82802023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82812023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82822023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82832023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82842023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82852023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82862023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82872023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82882023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82892023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82902023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82912023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82922023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82932023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82942023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82952023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82962023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82972023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82982023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
82992023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83002023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83012023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83022023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83032023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83042023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83052023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83062023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83072023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83082023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83092023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83102023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83112023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83122023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83132023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83142023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83152023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83162023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83172023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83182023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83192023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83202023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83212023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83222023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83232023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83242023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83252023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83262023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83272023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83282023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83292023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83302023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83312023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83322023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83332023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83342023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83352023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83362023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83372023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83382023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83392023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83402023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83412023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83422023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83432023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83442023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83452023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_office.net| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
83462023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_api.application| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
83472023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
83482023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83492023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83502023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83512023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83522023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83532023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83542023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83552023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83562023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83572023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83582023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83592023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83602023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83612023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83622023-05-10 16:35:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
83632023-05-10 16:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
83642023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83652023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83662023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83672023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83682023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83692023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83702023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83712023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83722023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83732023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83742023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83752023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83762023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83772023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83782023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83792023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83802023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83812023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83822023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83832023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83842023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83852023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83862023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83872023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83882023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83892023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83902023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83912023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83922023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83932023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83942023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83952023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83962023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83972023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83982023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
83992023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84002023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84012023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84022023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84032023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84042023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84052023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84062023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84072023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84082023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84092023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84102023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84112023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84122023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84132023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84142023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84152023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84162023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84172023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84182023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84192023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84202023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84212023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84222023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84232023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84242023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84252023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84262023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84272023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84282023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84292023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84302023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84312023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84322023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84332023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84342023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84352023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84362023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84372023-05-10 16:35:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
84382023-05-10 16:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
84392023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84402023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84412023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84422023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84432023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84442023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84452023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84462023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84472023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84482023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84492023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84502023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84512023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84522023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84532023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84542023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84552023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84562023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84572023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84582023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84592023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84602023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84612023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84622023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84632023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84642023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84652023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84662023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84672023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84682023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84692023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84702023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84712023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84722023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84732023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84742023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84752023-05-10 16:35:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
84762023-05-10 16:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
84772023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84782023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84792023-05-10 16:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
84802023-05-10 16:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
84812023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84822023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84832023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84842023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84852023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84862023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84872023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84882023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84892023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84902023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84912023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84922023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84932023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84942023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84952023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84962023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84972023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84982023-05-10 16:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
84992023-05-10 15:30:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
85002023-05-10 15:30:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
85012023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85022023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85032023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85042023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85052023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85062023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85072023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85082023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85092023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85102023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85112023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85122023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85132023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85142023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85152023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85162023-05-10 15:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
85172023-05-10 15:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
85182023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85192023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85202023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85212023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85222023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85232023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85242023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85252023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85262023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85272023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85282023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85292023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85302023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85312023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85322023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85332023-05-10 15:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
85342023-05-10 15:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
85352023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85362023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85372023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85382023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85392023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85402023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85412023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85422023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85432023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85442023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85452023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85462023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85472023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85482023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85492023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85502023-05-10 15:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
85512023-05-10 15:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
85522023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85532023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85542023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85552023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85562023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85572023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85582023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85592023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85602023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85612023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85622023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85632023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85642023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85652023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85662023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85672023-05-10 15:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
85682023-05-10 15:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
85692023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85702023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85712023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85722023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85732023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85742023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85752023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85762023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85772023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85782023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85792023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85802023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85812023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85822023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85832023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85842023-05-10 15:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
85852023-05-10 15:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
85862023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85872023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85882023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85892023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85902023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85912023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85922023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85932023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85942023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85952023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85962023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85972023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85982023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
85992023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86002023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86012023-05-10 15:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
86022023-05-10 15:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
86032023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86042023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86052023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86062023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86072023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86082023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86092023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86102023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86112023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86122023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86132023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86142023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86152023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86162023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86172023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86182023-05-10 15:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
86192023-05-10 15:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
86202023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86212023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86222023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86232023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86242023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86252023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86262023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86272023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86282023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86292023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86302023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86312023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86322023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86332023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86342023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86352023-05-10 15:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
86362023-05-10 15:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
86372023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86382023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86392023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86402023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86412023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86422023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86432023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86442023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86452023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86462023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86472023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86482023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86492023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86502023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86512023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86522023-05-10 15:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
86532023-05-10 15:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
86542023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86552023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86562023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86572023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86582023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86592023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86602023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86612023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86622023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86632023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86642023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86652023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86662023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86672023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86682023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86692023-05-10 15:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
86702023-05-10 15:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
86712023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86722023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86732023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86742023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86752023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86762023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86772023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86782023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86792023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86802023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86812023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86822023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86832023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86842023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86852023-05-10 15:29:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86862023-05-10 15:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
86872023-05-10 15:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
86882023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86892023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86902023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86912023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86922023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86932023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86942023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86952023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86962023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86972023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86982023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
86992023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87002023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87012023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87022023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87032023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
87042023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
87052023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87062023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87072023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87082023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87092023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87102023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87112023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87122023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87132023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87142023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87152023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87162023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87172023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87182023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87192023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87202023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
87212023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
87222023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87232023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87242023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87252023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87262023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87272023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87282023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87292023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87302023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87312023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87322023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87332023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87342023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87352023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87362023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87372023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
87382023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
87392023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87402023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87412023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87422023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87432023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87442023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87452023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87462023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87472023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87482023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87492023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87502023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87512023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87522023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87532023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87542023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
87552023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
87562023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87572023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87582023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87592023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87602023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87612023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87622023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87632023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87642023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87652023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87662023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87672023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87682023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87692023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87702023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87712023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
87722023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
87732023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87742023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87752023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87762023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87772023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87782023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87792023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87802023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87812023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87822023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87832023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87842023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87852023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87862023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87872023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87882023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
87892023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
87902023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
87912023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
87922023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87932023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87942023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87952023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87962023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87972023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87982023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
87992023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88002023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88012023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88022023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88032023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88042023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88052023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88062023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88072023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
88082023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
88092023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88102023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88112023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88122023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88132023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88142023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88152023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88162023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88172023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88182023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88192023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88202023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88212023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88222023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88232023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88242023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
88252023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
88262023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88272023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88282023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88292023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88302023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88312023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88322023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88332023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88342023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88352023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88362023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88372023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88382023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88392023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88402023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88412023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
88422023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
88432023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88442023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88452023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88462023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88472023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88482023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88492023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88502023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88512023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88522023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88532023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88542023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88552023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88562023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88572023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88582023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88592023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88602023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88612023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88622023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88632023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88642023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88652023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88662023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88672023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88682023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88692023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88702023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88712023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88722023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88732023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88742023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88752023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88762023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88772023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88782023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88792023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88802023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88812023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88822023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88832023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88842023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88852023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88862023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88872023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88882023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88892023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88902023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88912023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88922023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88932023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88942023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88952023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88962023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88972023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
88982023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
88992023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
89002023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89012023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89022023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89032023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89042023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89052023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89062023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89072023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89082023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89092023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89102023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89112023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89122023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89132023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89142023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89152023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89162023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89172023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89182023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89192023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89202023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89212023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89222023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89232023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89242023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89252023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89262023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89272023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89282023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89292023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89302023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89312023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89322023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89332023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89342023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89352023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89362023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89372023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89382023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89392023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89402023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89412023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89422023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89432023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89442023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89452023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89462023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89472023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89482023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89492023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89502023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89512023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89522023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89532023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89542023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89552023-05-10 15:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
89562023-05-10 15:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
89572023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89582023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89592023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89602023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89612023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89622023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89632023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89642023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89652023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89662023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89672023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89682023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89692023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89702023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89712023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89722023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89732023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89742023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89752023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89762023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89772023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89782023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89792023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89802023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89812023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89822023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89832023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89842023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89852023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89862023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89872023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89882023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89892023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89902023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89912023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89922023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89932023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89942023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89952023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89962023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89972023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89982023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
89992023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90002023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90012023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90022023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90032023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90042023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90052023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90062023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90072023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90082023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90092023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90102023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90112023-05-10 15:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90122023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
90132023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
90142023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90152023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90162023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90172023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90182023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90192023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90202023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90212023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90222023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90232023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90242023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90252023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90262023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90272023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90282023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90292023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90302023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90312023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90322023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90332023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90342023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90352023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90362023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90372023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90382023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90392023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90402023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90412023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90422023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90432023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90442023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90452023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90462023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90472023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90482023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90492023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90502023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90512023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90522023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90532023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90542023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90552023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90562023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90572023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90582023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90592023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90602023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90612023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90622023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90632023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90642023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90652023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90662023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90672023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90682023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90692023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90702023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90712023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90722023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90732023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90742023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90752023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90762023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90772023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90782023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90792023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90802023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90812023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90822023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90832023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90842023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90852023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90862023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90872023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90882023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90892023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90902023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90912023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90922023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90932023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90942023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90952023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90962023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90972023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90982023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
90992023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91002023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
91012023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
91022023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91032023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91042023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91052023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91062023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91072023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91082023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91092023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91102023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91112023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91122023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91132023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91142023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91152023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91162023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91172023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
91182023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
91192023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91202023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91212023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91222023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91232023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91242023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91252023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91262023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91272023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91282023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91292023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91302023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91312023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91322023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91332023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91342023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
91352023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
91362023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91372023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91382023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91392023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91402023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91412023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91422023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91432023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91442023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91452023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91462023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91472023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91482023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91492023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91502023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91512023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
91522023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
91532023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91542023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91552023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91562023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91572023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91582023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91592023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91602023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91612023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91622023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91632023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91642023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91652023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91662023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91672023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91682023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
91692023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
91702023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91712023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91722023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91732023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91742023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91752023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91762023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91772023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91782023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91792023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91802023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91812023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91822023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91832023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91842023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91852023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
91862023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
91872023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91882023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91892023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91902023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91912023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91922023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91932023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91942023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91952023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91962023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91972023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91982023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
91992023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92002023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92012023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92022023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
92032023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
92042023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92052023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92062023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92072023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92082023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92092023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92102023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92112023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92122023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92132023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92142023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92152023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92162023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92172023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92182023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92192023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
92202023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
92212023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92222023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92232023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92242023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92252023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92262023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92272023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92282023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92292023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92302023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92312023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92322023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92332023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92342023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92352023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92362023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
92372023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
92382023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92392023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92402023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92412023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92422023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92432023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92442023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92452023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92462023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92472023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92482023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92492023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92502023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92512023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92522023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92532023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
92542023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
92552023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92562023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92572023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92582023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92592023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92602023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92612023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92622023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92632023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92642023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92652023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92662023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92672023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92682023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92692023-05-10 15:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92702023-05-10 15:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
92712023-05-10 15:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
92722023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92732023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92742023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92752023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92762023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92772023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92782023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92792023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92802023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92812023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92822023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92832023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92842023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92852023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92862023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92872023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
92882023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
92892023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
92902023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
92912023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92922023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92932023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92942023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92952023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92962023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92972023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92982023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
92992023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93002023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93012023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93022023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93032023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93042023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93052023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93062023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
93072023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
93082023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93092023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93102023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93112023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93122023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93132023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93142023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93152023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93162023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93172023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93182023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93192023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93202023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93212023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93222023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93232023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
93242023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
93252023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93262023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93272023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93282023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93292023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93302023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93312023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93322023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93332023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93342023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93352023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93362023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93372023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93382023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93392023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93402023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
93412023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
93422023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93432023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93442023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93452023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93462023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93472023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93482023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93492023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93502023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93512023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93522023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93532023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93542023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93552023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93562023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93572023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
93582023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
93592023-05-10 15:26:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
93602023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93612023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93622023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93632023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93642023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93652023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93662023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93672023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93682023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93692023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93702023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93712023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93722023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93732023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93742023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93752023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
93762023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
93772023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93782023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93792023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93802023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93812023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93822023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93832023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93842023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93852023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93862023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93872023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93882023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93892023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93902023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93912023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93922023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
93932023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
93942023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93952023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93962023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93972023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93982023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
93992023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94002023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94012023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94022023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94032023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94042023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94052023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94062023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94072023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94082023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94092023-05-10 15:26:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
94102023-05-10 15:26:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
94112023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
94122023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
94132023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94142023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94152023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94162023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94172023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94182023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94192023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94202023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94212023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94222023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94232023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94242023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94252023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94262023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94272023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94282023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
94292023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
94302023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94312023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94322023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94332023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94342023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94352023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94362023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94372023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94382023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94392023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94402023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94412023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94422023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94432023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94442023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94452023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
94462023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
94472023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94482023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94492023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94502023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94512023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94522023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94532023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94542023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94552023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94562023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94572023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94582023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94592023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94602023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94612023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94622023-05-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
94632023-05-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
94642023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94652023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94662023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94672023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94682023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94692023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94702023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94712023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94722023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94732023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94742023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94752023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94762023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94772023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94782023-05-10 15:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94792023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
94802023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
94812023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94822023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94832023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94842023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94852023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94862023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94872023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94882023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94892023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94902023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94912023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94922023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94932023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94942023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94952023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
94962023-05-10 15:25:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x63c4| Process Name: C:\Windows\System32\LogonUI.exe
94972023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
94982023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
94992023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95002023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95012023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95022023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95032023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95042023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95052023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95062023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95072023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95082023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95092023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95102023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95112023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95122023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95132023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95142023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
95152023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
95162023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95172023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95182023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95192023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95202023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95212023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95222023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95232023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95242023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95252023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95262023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95272023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95282023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95292023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95302023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95312023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
95322023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
95332023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95342023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95352023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95362023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95372023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95382023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95392023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95402023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95412023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95422023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95432023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95442023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95452023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95462023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95472023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95482023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
95492023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
95502023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95512023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95522023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95532023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95542023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95552023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95562023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95572023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95582023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95592023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95602023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95612023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95622023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95632023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95642023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95652023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
95662023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
95672023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95682023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95692023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95702023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95712023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95722023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95732023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95742023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95752023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95762023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95772023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95782023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95792023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95802023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95812023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95822023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
95832023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
95842023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95852023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95862023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95872023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95882023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95892023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95902023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95912023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95922023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95932023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95942023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95952023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95962023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95972023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95982023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
95992023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
96002023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
96012023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96022023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96032023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96042023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96052023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96062023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96072023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96082023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96092023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96102023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96112023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96122023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96132023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96142023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96152023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96162023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
96172023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
96182023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96192023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96202023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96212023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96222023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96232023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96242023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96252023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96262023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96272023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96282023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96292023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96302023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96312023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96322023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96332023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
96342023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
96352023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96362023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96372023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96382023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96392023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96402023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96412023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96422023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96432023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96442023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96452023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96462023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96472023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96482023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96492023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96502023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
96512023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
96522023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96532023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96542023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96552023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96562023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96572023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96582023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96592023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96602023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96612023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96622023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96632023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96642023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96652023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96662023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96672023-05-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
96682023-05-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
96692023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96702023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96712023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96722023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96732023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96742023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96752023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96762023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96772023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96782023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96792023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96802023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96812023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96822023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96832023-05-10 15:25:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96842023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
96852023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
96862023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96872023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96882023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96892023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96902023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96912023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96922023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96932023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96942023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96952023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96962023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96972023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96982023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
96992023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97002023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97012023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
97022023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
97032023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97042023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97052023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97062023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97072023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97082023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97092023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97102023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97112023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97122023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97132023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97142023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97152023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97162023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97172023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97182023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
97192023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
97202023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97212023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97222023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97232023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97242023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97252023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97262023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97272023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97282023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97292023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97302023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97312023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97322023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97332023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97342023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97352023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
97362023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
97372023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97382023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97392023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97402023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97412023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97422023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97432023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97442023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97452023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97462023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97472023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97482023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97492023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97502023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97512023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97522023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
97532023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
97542023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97552023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97562023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97572023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97582023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97592023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97602023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97612023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97622023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97632023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97642023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97652023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97662023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97672023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97682023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97692023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
97702023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
97712023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97722023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97732023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97742023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97752023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97762023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97772023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97782023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97792023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97802023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97812023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97822023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97832023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97842023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97852023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97862023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
97872023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
97882023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97892023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97902023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97912023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97922023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97932023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97942023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97952023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97962023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97972023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97982023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
97992023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98002023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98012023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98022023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98032023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
98042023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
98052023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98062023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98072023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98082023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98092023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98102023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98112023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98122023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98132023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98142023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98152023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98162023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98172023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98182023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98192023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98202023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
98212023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
98222023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98232023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98242023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98252023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98262023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98272023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98282023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98292023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98302023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98312023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98322023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98332023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98342023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98352023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98362023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98372023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
98382023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
98392023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98402023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98412023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98422023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98432023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98442023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98452023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98462023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98472023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98482023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98492023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98502023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98512023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98522023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98532023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98542023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
98552023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
98562023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98572023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98582023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98592023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98602023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98612023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98622023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98632023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98642023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98652023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98662023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98672023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98682023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98692023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98702023-05-10 15:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98712023-05-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
98722023-05-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
98732023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98742023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98752023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98762023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98772023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98782023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98792023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98802023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98812023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98822023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98832023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98842023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98852023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98862023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98872023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98882023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
98892023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
98902023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98912023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98922023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98932023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98942023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98952023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98962023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98972023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98982023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
98992023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99002023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99012023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99022023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99032023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99042023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99052023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
99062023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
99072023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99082023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99092023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99102023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99112023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99122023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99132023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99142023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99152023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99162023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99172023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99182023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99192023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99202023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99212023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99222023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
99232023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
99242023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99252023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99262023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99272023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99282023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99292023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99302023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99312023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99322023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99332023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99342023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99352023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99362023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99372023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99382023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99392023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
99402023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
99412023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99422023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99432023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99442023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99452023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99462023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99472023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99482023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99492023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99502023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99512023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99522023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99532023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99542023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99552023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99562023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
99572023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
99582023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
99592023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
99602023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99612023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99622023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99632023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99642023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99652023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99662023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99672023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99682023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99692023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99702023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99712023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99722023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99732023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99742023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99752023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
99762023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
99772023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99782023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99792023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99802023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99812023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99822023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99832023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99842023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99852023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99862023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99872023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99882023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99892023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99902023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99912023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99922023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
99932023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
99942023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99952023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99962023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99972023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99982023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
99992023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100002023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100012023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100022023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100032023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100042023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100052023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100062023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100072023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100082023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100092023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
100102023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
100112023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
100122023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
100132023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100142023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100152023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100162023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100172023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100182023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100192023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100202023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100212023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100222023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100232023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100242023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100252023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100262023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100272023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100282023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100292023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100302023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100312023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100322023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100332023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100342023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100352023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100362023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100372023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100382023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100392023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100402023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100412023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100422023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100432023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100442023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100452023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100462023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100472023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100482023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100492023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100502023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100512023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100522023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100532023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100542023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100552023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100562023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100572023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100582023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100592023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100602023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100612023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100622023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100632023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100642023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100652023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100662023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100672023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100682023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100692023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100702023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100712023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100722023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100732023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100742023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100752023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100762023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100772023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100782023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100792023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100802023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100812023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100822023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100832023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100842023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100852023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100862023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100872023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100882023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100892023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100902023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100912023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100922023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100932023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100942023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100952023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100962023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100972023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100982023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
100992023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101002023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101012023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101022023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101032023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101042023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101052023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101062023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101072023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101082023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101092023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101102023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101112023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101122023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101132023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101142023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101152023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101162023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101172023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101182023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101192023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101202023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101212023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101222023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101232023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101242023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101252023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101262023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101272023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101282023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101292023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101302023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101312023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101322023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101332023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101342023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101352023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101362023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101372023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101382023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101392023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101402023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101412023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101422023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101432023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101442023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101452023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101462023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101472023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101482023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101492023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101502023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101512023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101522023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101532023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101542023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101552023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101562023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101572023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101582023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101592023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101602023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101612023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101622023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101632023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101642023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101652023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101662023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101672023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101682023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101692023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101702023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101712023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101722023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101732023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101742023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101752023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101762023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101772023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101782023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101792023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101802023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101812023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101822023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101832023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101842023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101852023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101862023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101872023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101882023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101892023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101902023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101912023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101922023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101932023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101942023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101952023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101962023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101972023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101982023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
101992023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102002023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102012023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102022023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102032023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102042023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102052023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102062023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102072023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102082023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102092023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102102023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102112023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102122023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102132023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102142023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102152023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102162023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102172023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102182023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102192023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102202023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102212023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102222023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102232023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102242023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102252023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102262023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102272023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102282023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102292023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102302023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102312023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102322023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102332023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102342023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102352023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102362023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102372023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102382023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102392023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102402023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102412023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102422023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102432023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102442023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102452023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102462023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102472023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102482023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102492023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102502023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102512023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102522023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102532023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102542023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102552023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102562023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102572023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102582023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102592023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102602023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102612023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102622023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102632023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102642023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102652023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102662023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102672023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102682023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102692023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102702023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102712023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102722023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102732023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102742023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102752023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102762023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102772023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102782023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102792023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102802023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102812023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102822023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102832023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102842023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102852023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102862023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102872023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102882023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102892023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102902023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102912023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102922023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102932023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102942023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102952023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102962023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102972023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102982023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
102992023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103002023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103012023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103022023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103032023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103042023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103052023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103062023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103072023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103082023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103092023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103102023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103112023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103122023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103132023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103142023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103152023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103162023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103172023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103182023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103192023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103202023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103212023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103222023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103232023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103242023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103252023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103262023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103272023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103282023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103292023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103302023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103312023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103322023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103332023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103342023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103352023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103362023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103372023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103382023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103392023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103402023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103412023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103422023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103432023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103442023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103452023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103462023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103472023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103482023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103492023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103502023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103512023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103522023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103532023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103542023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103552023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103562023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103572023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103582023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103592023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103602023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103612023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103622023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103632023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103642023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103652023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103662023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103672023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103682023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103692023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103702023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103712023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103722023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103732023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103742023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103752023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103762023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103772023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103782023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103792023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103802023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103812023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103822023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103832023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103842023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103852023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103862023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103872023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103882023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103892023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103902023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103912023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103922023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103932023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103942023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103952023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103962023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103972023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103982023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
103992023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104002023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104012023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104022023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104032023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104042023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104052023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104062023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104072023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104082023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104092023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104102023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104112023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104122023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104132023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104142023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104152023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104162023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104172023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104182023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104192023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104202023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104212023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104222023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104232023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104242023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104252023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104262023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104272023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104282023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104292023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104302023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104312023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104322023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104332023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104342023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104352023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104362023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104372023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104382023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104392023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104402023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104412023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104422023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104432023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
104442023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
104452023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104462023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104472023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104482023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104492023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104502023-05-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
104512023-05-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
104522023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104532023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104542023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104552023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104562023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104572023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104582023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104592023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104602023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104612023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104622023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104632023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104642023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104652023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104662023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104672023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104682023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104692023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104702023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104712023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104722023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104732023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104742023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104752023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104762023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104772023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104782023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104792023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104802023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104812023-05-10 15:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
104822023-05-10 15:23:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
104832023-05-10 15:23:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
104842023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
104852023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
104862023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
104872023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
104882023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
104892023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
104902023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
104912023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
104922023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
104932023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
104942023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
104952023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
104962023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
104972023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
104982023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
104992023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
105002023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105012023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105022023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105032023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105042023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105052023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105062023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105072023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105082023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105092023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105102023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105112023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105122023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105132023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105142023-05-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105152023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
105162023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
105172023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
105182023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
105192023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
105202023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
105212023-05-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
105222023-05-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
105232023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
105242023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
105252023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
105262023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
105272023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
105282023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
105292023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105302023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105312023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105322023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105332023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105342023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105352023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105362023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105372023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105382023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105392023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105402023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105412023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105422023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105432023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105442023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105452023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105462023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105472023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105482023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105492023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105502023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105512023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105522023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105532023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105542023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105552023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105562023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105572023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105582023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105592023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105602023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105612023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105622023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105632023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105642023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105652023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105662023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105672023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105682023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105692023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105702023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105712023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105722023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105732023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105742023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105752023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105762023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105772023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105782023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105792023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105802023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105812023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105822023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105832023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105842023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105852023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105862023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105872023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105882023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105892023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105902023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105912023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105922023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105932023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105942023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105952023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105962023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105972023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105982023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
105992023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106002023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106012023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106022023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106032023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106042023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106052023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106062023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106072023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106082023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106092023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106102023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106112023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106122023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106132023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106142023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106152023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106162023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106172023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106182023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106192023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106202023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106212023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106222023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106232023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106242023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106252023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106262023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106272023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106282023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106292023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106302023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106312023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106322023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106332023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106342023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106352023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106362023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106372023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106382023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106392023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106402023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106412023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106422023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106432023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106442023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106452023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106462023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106472023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106482023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106492023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106502023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106512023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106522023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106532023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106542023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106552023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106562023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106572023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106582023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106592023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106602023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106612023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106622023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106632023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106642023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106652023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106662023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106672023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106682023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106692023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106702023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106712023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106722023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106732023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106742023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106752023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106762023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106772023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106782023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106792023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106802023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106812023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106822023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106832023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106842023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106852023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106862023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106872023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106882023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106892023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106902023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106912023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106922023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106932023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106942023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106952023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106962023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106972023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106982023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
106992023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107002023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107012023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107022023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107032023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107042023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107052023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107062023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107072023-05-10 15:21:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
107082023-05-10 15:21:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
107092023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107102023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107112023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107122023-05-10 15:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107132023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107142023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107152023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107162023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107172023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107182023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107192023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107202023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107212023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107222023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107232023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107242023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107252023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107262023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107272023-05-10 15:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107282023-05-10 15:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107292023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107302023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107312023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107322023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107332023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107342023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107352023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107362023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107372023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107382023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107392023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107402023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107412023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
107422023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
107432023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107442023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107452023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107462023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107472023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107482023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107492023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107502023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107512023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107522023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107532023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107542023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107552023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107562023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107572023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107582023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107592023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107602023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107612023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107622023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107632023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107642023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107652023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107662023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107672023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107682023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107692023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107702023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107712023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107722023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107732023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107742023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107752023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107762023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107772023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107782023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107792023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107802023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107812023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107822023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107832023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107842023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107852023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107862023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107872023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107882023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107892023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107902023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107912023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107922023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107932023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107942023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107952023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107962023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107972023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107982023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
107992023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108002023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108012023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108022023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108032023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108042023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108052023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108062023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108072023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108082023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108092023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108102023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108112023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108122023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108132023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108142023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108152023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108162023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108172023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108182023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108192023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108202023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108212023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108222023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108232023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108242023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108252023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108262023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108272023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108282023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108292023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108302023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108312023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108322023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108332023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108342023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108352023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108362023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108372023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108382023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108392023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108402023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108412023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108422023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108432023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108442023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108452023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108462023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108472023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108482023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108492023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108502023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108512023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108522023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108532023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108542023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108552023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108562023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108572023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108582023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108592023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108602023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108612023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108622023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108632023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108642023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108652023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108662023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108672023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108682023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108692023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108702023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108712023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108722023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108732023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108742023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108752023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108762023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108772023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108782023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108792023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108802023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108812023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108822023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108832023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108842023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108852023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108862023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108872023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108882023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108892023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108902023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108912023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108922023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108932023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108942023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108952023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108962023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108972023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108982023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
108992023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109002023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109012023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109022023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109032023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109042023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109052023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109062023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109072023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109082023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109092023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109102023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109112023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109122023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109132023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109142023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109152023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109162023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109172023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109182023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109192023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109202023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109212023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109222023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109232023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109242023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109252023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109262023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109272023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109282023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109292023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109302023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109312023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109322023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109332023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109342023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109352023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109362023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109372023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109382023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109392023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109402023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109412023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109422023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109432023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109442023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109452023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109462023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109472023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109482023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109492023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109502023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109512023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109522023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109532023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109542023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109552023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109562023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109572023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109582023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109592023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109602023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109612023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109622023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109632023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109642023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109652023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109662023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109672023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109682023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109692023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109702023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109712023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109722023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109732023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109742023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109752023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109762023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109772023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109782023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109792023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109802023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109812023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109822023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109832023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109842023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109852023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109862023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109872023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109882023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109892023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109902023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109912023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109922023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109932023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109942023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109952023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109962023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109972023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109982023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
109992023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110002023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110012023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110022023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110032023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110042023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110052023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110062023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110072023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110082023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110092023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110102023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110112023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110122023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110132023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110142023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110152023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110162023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110172023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110182023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110192023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110202023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110212023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110222023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110232023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110242023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110252023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110262023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110272023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110282023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110292023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110302023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110312023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110322023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110332023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110342023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110352023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110362023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110372023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110382023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110392023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110402023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110412023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110422023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110432023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110442023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110452023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110462023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110472023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110482023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110492023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110502023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110512023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110522023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110532023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110542023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110552023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110562023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110572023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110582023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110592023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110602023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110612023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110622023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110632023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110642023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110652023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110662023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110672023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110682023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110692023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110702023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110712023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110722023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110732023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110742023-05-10 15:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
110752023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110762023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110772023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110782023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110792023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110802023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110812023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110822023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110832023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110842023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110852023-05-10 15:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110862023-05-10 15:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110872023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110882023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110892023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110902023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110912023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110922023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110932023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110942023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110952023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
110962023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
110972023-05-10 15:19:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
110982023-05-10 15:19:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
110992023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111002023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111012023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111022023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111032023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111042023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111052023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111062023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111072023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111082023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111092023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111102023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111112023-05-10 15:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111122023-05-10 15:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111132023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111142023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111152023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111162023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111172023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111182023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111192023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111202023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111212023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111222023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111232023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111242023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111252023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111262023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111272023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111282023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111292023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111302023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111312023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111322023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111332023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111342023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111352023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111362023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111372023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111382023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111392023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111402023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111412023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111422023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111432023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111442023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111452023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111462023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111472023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111482023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111492023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111502023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111512023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111522023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111532023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111542023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111552023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111562023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111572023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111582023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111592023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111602023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111612023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111622023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111632023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111642023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111652023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111662023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111672023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111682023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111692023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111702023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111712023-05-10 15:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
111722023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111732023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111742023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111752023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111762023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111772023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111782023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111792023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111802023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111812023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111822023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111832023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111842023-05-10 15:18:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
111852023-05-10 15:18:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
111862023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111872023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111882023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111892023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111902023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111912023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111922023-05-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111932023-05-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111942023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111952023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
111962023-05-10 15:17:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
111972023-05-10 15:17:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
111982023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
111992023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
112002023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
112012023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
112022023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
112032023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
112042023-05-10 15:17:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
112052023-05-10 15:17:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
112062023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
112072023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
112082023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
112092023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
112102023-05-10 15:17:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
112112023-05-10 15:17:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
112122023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
112132023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
112142023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
112152023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
112162023-05-10 15:17:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
112172023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
112182023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
112192023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112202023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112212023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112222023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112232023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112242023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112252023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112262023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112272023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112282023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112292023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112302023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112312023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112322023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112332023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112342023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112352023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112362023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112372023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112382023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112392023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112402023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112412023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112422023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112432023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112442023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112452023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112462023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112472023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112482023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112492023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112502023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112512023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112522023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112532023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112542023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112552023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112562023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112572023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112582023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112592023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112602023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112612023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112622023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112632023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112642023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112652023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112662023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112672023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112682023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112692023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112702023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112712023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112722023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112732023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112742023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
112752023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
112762023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112772023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112782023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112792023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112802023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112812023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112822023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112832023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112842023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112852023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112862023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112872023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112882023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112892023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112902023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112912023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112922023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112932023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112942023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112952023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112962023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112972023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112982023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
112992023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113002023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113012023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113022023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113032023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113042023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113052023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113062023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113072023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113082023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113092023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113102023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113112023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113122023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113132023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113142023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113152023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113162023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113172023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113182023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113192023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113202023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113212023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113222023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113232023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113242023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113252023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113262023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113272023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113282023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113292023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113302023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113312023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113322023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113332023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113342023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113352023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113362023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113372023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113382023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113392023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
113402023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
113412023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
113422023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113432023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113442023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113452023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113462023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113472023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
113482023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113492023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113502023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113512023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113522023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113532023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113542023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113552023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113562023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113572023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113582023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113592023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113602023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113612023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113622023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113632023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113642023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113652023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113662023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113672023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113682023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113692023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113702023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113712023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113722023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113732023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113742023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113752023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113762023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113772023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113782023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113792023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113802023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113812023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113822023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113832023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113842023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113852023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113862023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113872023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113882023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113892023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113902023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113912023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113922023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113932023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113942023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113952023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113962023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113972023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113982023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
113992023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114002023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114012023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114022023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114032023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114042023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114052023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114062023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114072023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114082023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114092023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114102023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114112023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114122023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114132023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114142023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114152023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114162023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114172023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114182023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114192023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114202023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114212023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114222023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114232023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114242023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114252023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114262023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114272023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114282023-05-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
114292023-05-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
114302023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114312023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114322023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114332023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114342023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114352023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114362023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114372023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114382023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114392023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114402023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114412023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114422023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114432023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114442023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114452023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114462023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114472023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114482023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114492023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114502023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114512023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114522023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114532023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114542023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114552023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114562023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114572023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114582023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114592023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114602023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114612023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114622023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114632023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114642023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114652023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114662023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114672023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114682023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114692023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114702023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114712023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114722023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114732023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114742023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114752023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114762023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114772023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114782023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114792023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114802023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114812023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114822023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114832023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114842023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114852023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114862023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114872023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114882023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114892023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114902023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114912023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114922023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114932023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114942023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114952023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114962023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114972023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114982023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
114992023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115002023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115012023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115022023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115032023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115042023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115052023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115062023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115072023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115082023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115092023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115102023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115112023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115122023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115132023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115142023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115152023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115162023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115172023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115182023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115192023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115202023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115212023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115222023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115232023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115242023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115252023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115262023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115272023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115282023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115292023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115302023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115312023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115322023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115332023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115342023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115352023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115362023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115372023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115382023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115392023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115402023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115412023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115422023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115432023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115442023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115452023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115462023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115472023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115482023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115492023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115502023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115512023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115522023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115532023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115542023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115552023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115562023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115572023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115582023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115592023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115602023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115612023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115622023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115632023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115642023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115652023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115662023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115672023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115682023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115692023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115702023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115712023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115722023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115732023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115742023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115752023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115762023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115772023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115782023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115792023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115802023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115812023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115822023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115832023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115842023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115852023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115862023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115872023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115882023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115892023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115902023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115912023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115922023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115932023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115942023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115952023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115962023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115972023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115982023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
115992023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116002023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116012023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116022023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116032023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116042023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116052023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116062023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116072023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116082023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116092023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116102023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116112023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116122023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116132023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116142023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116152023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116162023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116172023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116182023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116192023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116202023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116212023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116222023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116232023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116242023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116252023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116262023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116272023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116282023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116292023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116302023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116312023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116322023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116332023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116342023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116352023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116362023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116372023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116382023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116392023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116402023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116412023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116422023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116432023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116442023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116452023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116462023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116472023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116482023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116492023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116502023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116512023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116522023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116532023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116542023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116552023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116562023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116572023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116582023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116592023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116602023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116612023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116622023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116632023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116642023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116652023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116662023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116672023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116682023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116692023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116702023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116712023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116722023-05-10 15:17:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116732023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116742023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116752023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116762023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116772023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116782023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
116792023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
116802023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116812023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116822023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116832023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116842023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116852023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116862023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116872023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116882023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116892023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116902023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116912023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116922023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116932023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116942023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116952023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116962023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116972023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116982023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
116992023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117002023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117012023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117022023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117032023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117042023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117052023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117062023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117072023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117082023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117092023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117102023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117112023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117122023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117132023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117142023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117152023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117162023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117172023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117182023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117192023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117202023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117212023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117222023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117232023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117242023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117252023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117262023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117272023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117282023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117292023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117302023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117312023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117322023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117332023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117342023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117352023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117362023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117372023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117382023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117392023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117402023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117412023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117422023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117432023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117442023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117452023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117462023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117472023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117482023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117492023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117502023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117512023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117522023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117532023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117542023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117552023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117562023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117572023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117582023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117592023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117602023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117612023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117622023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117632023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117642023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117652023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117662023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117672023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117682023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117692023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117702023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117712023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117722023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117732023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117742023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117752023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117762023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117772023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117782023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117792023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117802023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117812023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117822023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117832023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117842023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117852023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117862023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117872023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117882023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117892023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117902023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117912023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117922023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117932023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117942023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117952023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117962023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117972023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117982023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
117992023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118002023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118012023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118022023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118032023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118042023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118052023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118062023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118072023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118082023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118092023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118102023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118112023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118122023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118132023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118142023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118152023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118162023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118172023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118182023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118192023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118202023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118212023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118222023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118232023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118242023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118252023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118262023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118272023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118282023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118292023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118302023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118312023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118322023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118332023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118342023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118352023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118362023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118372023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118382023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118392023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118402023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118412023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118422023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118432023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
118442023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118452023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118462023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118472023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118482023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118492023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118502023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118512023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118522023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118532023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118542023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118552023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118562023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118572023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118582023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118592023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118602023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118612023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118622023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118632023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118642023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118652023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118662023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118672023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118682023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118692023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118702023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118712023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118722023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118732023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118742023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118752023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118762023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118772023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118782023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118792023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118802023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118812023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118822023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118832023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118842023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118852023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118862023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118872023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118882023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118892023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118902023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118912023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118922023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118932023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118942023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118952023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118962023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118972023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118982023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
118992023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119002023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119012023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119022023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119032023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119042023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119052023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119062023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119072023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119082023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119092023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119102023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119112023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119122023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119132023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119142023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119152023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119162023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119172023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119182023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119192023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119202023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119212023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119222023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119232023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119242023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119252023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119262023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119272023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119282023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119292023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119302023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119312023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119322023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119332023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119342023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119352023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119362023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119372023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119382023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119392023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119402023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119412023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
119422023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
119432023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119442023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119452023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119462023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119472023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119482023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119492023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119502023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119512023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119522023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119532023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119542023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119552023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119562023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119572023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119582023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119592023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119602023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119612023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119622023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119632023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119642023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119652023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119662023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119672023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119682023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119692023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119702023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119712023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119722023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
119732023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
119742023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119752023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119762023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119772023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119782023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119792023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119802023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119812023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119822023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119832023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119842023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119852023-05-10 15:16:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
119862023-05-10 15:16:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
119872023-05-10 15:16:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
119882023-05-10 15:16:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
119892023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119902023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119912023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119922023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
119932023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
119942023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
119952023-05-10 15:16:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x5FBBBA4||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
119962023-05-10 15:16:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x5FB8444||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
119972023-05-10 15:16:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x5FB8501||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
119982023-05-10 15:16:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x5FBC061||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
119992023-05-10 15:16:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5FBBBA4||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
120002023-05-10 15:16:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5FBC061| Linked Logon ID: 0x5FBBBA4| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
120012023-05-10 15:16:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5FBBBA4| Linked Logon ID: 0x5FBC061| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
120022023-05-10 15:16:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
120032023-05-10 15:16:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
120042023-05-10 15:16:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
120052023-05-10 15:16:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
120062023-05-10 15:16:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5FB8444||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
120072023-05-10 15:16:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5FB8501| Linked Logon ID: 0x5FB8444| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
120082023-05-10 15:16:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5FB8444| Linked Logon ID: 0x5FB8501| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
120092023-05-10 15:16:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
120102023-05-10 15:16:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
120112023-05-10 15:16:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
120122023-05-10 15:16:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
120132023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120142023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120152023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120162023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120172023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120182023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120192023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120202023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120212023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120222023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120232023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120242023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120252023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120262023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120272023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120282023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120292023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120302023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120312023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120322023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120332023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120342023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120352023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120362023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120372023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120382023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120392023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120402023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120412023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120422023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120432023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120442023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120452023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120462023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120472023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120482023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120492023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120502023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120512023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120522023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120532023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120542023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120552023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120562023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120572023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120582023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120592023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120602023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120612023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120622023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120632023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120642023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120652023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120662023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120672023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120682023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120692023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120702023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120712023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120722023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120732023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120742023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120752023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120762023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120772023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120782023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120792023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120802023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120812023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120822023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120832023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120842023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120852023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120862023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120872023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
120882023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
120892023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120902023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120912023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120922023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120932023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120942023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120952023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120962023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120972023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120982023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
120992023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121002023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121012023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121022023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121032023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121042023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121052023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121062023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121072023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121082023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121092023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121102023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121112023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121122023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121132023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121142023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121152023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121162023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121172023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121182023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121192023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121202023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121212023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121222023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121232023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121242023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121252023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121262023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121272023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121282023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121292023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121302023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121312023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121322023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121332023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121342023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121352023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121362023-05-10 15:16:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121372023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121382023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121392023-05-10 15:16:00Microsoft-Windows-Security-Auditing4799Security Group ManagementA security-enabled local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Group:| Security ID: BUILTIN\Administrators| Group Name: Administrators| Group Domain: Builtin||Process Information:| Process ID: 0x6cc0| Process Name: C:\Windows\System32\svchost.exe
121402023-05-10 15:16:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x840| Process Name: C:\Windows\System32\LogonUI.exe
121412023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121422023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121432023-05-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
121442023-05-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
121452023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121462023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121472023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121482023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121492023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121502023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121512023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121522023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121532023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121542023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121552023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121562023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121572023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121582023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121592023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121602023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121612023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121622023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121632023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121642023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121652023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121662023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121672023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121682023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121692023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121702023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121712023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121722023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121732023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121742023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121752023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121762023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121772023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121782023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121792023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121802023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121812023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121822023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121832023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121842023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121852023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121862023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121872023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121882023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121892023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121902023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121912023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121922023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121932023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121942023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121952023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121962023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121972023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121982023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
121992023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122002023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122012023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122022023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122032023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122042023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122052023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122062023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122072023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122082023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122092023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122102023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122112023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122122023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122132023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122142023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122152023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122162023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122172023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122182023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122192023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122202023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122212023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122222023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122232023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122242023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122252023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122262023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122272023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122282023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122292023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122302023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122312023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122322023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122332023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122342023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122352023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122362023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122372023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122382023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122392023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122402023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122412023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122422023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122432023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122442023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122452023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122462023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122472023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122482023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122492023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122502023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122512023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122522023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122532023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122542023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122552023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122562023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122572023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122582023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122592023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122602023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122612023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122622023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122632023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122642023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122652023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122662023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122672023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122682023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122692023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122702023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122712023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122722023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122732023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122742023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122752023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122762023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122772023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122782023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122792023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122802023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122812023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122822023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122832023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122842023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122852023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122862023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122872023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122882023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122892023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122902023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122912023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122922023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122932023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122942023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122952023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122962023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122972023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122982023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
122992023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123002023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123012023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123022023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123032023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123042023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123052023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123062023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123072023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123082023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123092023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123102023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123112023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123122023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123132023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123142023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123152023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123162023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123172023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123182023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123192023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123202023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123212023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123222023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123232023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123242023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123252023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123262023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123272023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123282023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123292023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123302023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123312023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123322023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123332023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123342023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123352023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123362023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123372023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123382023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123392023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123402023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123412023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123422023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123432023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123442023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123452023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123462023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123472023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123482023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123492023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123502023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123512023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123522023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123532023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123542023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123552023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123562023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123572023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123582023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123592023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123602023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123612023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123622023-05-10 02:13:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
123632023-05-10 02:13:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
123642023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123652023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123662023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123672023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123682023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123692023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123702023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123712023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123722023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123732023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123742023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123752023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123762023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123772023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123782023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123792023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123802023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123812023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123822023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123832023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123842023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123852023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123862023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123872023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123882023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123892023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123902023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123912023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123922023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123932023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123942023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123952023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123962023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123972023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123982023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
123992023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124002023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124012023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124022023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124032023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124042023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124052023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124062023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124072023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124082023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124092023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124102023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124112023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124122023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124132023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124142023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124152023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124162023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124172023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124182023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124192023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124202023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124212023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124222023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124232023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124242023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124252023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124262023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124272023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124282023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124292023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124302023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_api.application| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124312023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_office.net| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124322023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124332023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124342023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124352023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124362023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124372023-05-10 02:13:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
124382023-05-10 02:13:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
124392023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124402023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
124412023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124422023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
124432023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124442023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
124452023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124462023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
124472023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124482023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
124492023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124502023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
124512023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124522023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
124532023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124542023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
124552023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124562023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
124572023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124582023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
124592023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124602023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124612023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124622023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124632023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124642023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124652023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124662023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124672023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124682023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124692023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124702023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124712023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
124722023-05-10 02:13:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
124732023-05-10 02:13:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
124742023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124752023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124762023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124772023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124782023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124792023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124802023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124812023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124822023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124832023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124842023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124852023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124862023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124872023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124882023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124892023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124902023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124912023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124922023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124932023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124942023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124952023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124962023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124972023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124982023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
124992023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125002023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125012023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125022023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125032023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125042023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125052023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125062023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125072023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125082023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125092023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125102023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125112023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125122023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125132023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125142023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125152023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125162023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125172023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125182023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125192023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125202023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125212023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125222023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125232023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125242023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
125252023-05-10 02:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125262023-05-10 02:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125272023-05-10 02:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125282023-05-10 02:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125292023-05-10 02:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125302023-05-10 02:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125312023-05-10 02:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125322023-05-10 02:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125332023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
125342023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
125352023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
125362023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
125372023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125382023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125392023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125402023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125412023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125422023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125432023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125442023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125452023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125462023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125472023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125482023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125492023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125502023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125512023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125522023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125532023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125542023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125552023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125562023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125572023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125582023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125592023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125602023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125612023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125622023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125632023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125642023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125652023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125662023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125672023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125682023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125692023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125702023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125712023-05-10 02:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125722023-05-10 02:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
125732023-05-10 02:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
125742023-05-10 02:13:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
125752023-05-10 02:13:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
125762023-04-10 22:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
125772023-04-10 22:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
125782023-04-10 22:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125792023-04-10 22:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125802023-04-10 22:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125812023-04-10 22:13:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
125822023-04-10 22:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125832023-04-10 22:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125842023-04-10 22:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125852023-04-10 22:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125862023-04-10 22:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125872023-04-10 22:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125882023-04-10 22:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125892023-04-10 22:13:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
125902023-04-10 22:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
125912023-04-10 22:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
125922023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
125932023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
125942023-04-10 22:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125952023-04-10 22:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125962023-04-10 22:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125972023-04-10 22:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125982023-04-10 22:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
125992023-04-10 22:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
126002023-04-10 22:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
126012023-04-10 22:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
126022023-04-10 22:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
126032023-04-10 22:12:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
126042023-04-10 22:12:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
126052023-04-10 22:12:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
126062023-04-10 22:12:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
126072023-04-10 22:12:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
126082023-04-10 22:12:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
126092023-04-10 22:12:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
126102023-04-10 22:12:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6e30| Process Name: C:\Windows\System32\taskhostw.exe
126112023-04-10 22:12:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
126122023-04-10 22:12:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
126132023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126142023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126152023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126162023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126172023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126182023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126192023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126202023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126212023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126222023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126232023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126242023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126252023-04-10 22:12:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
126262023-04-10 22:12:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
126272023-04-10 22:12:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
126282023-04-10 22:12:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
126292023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126302023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126312023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126322023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126332023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126342023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126352023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126362023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126372023-04-10 22:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126382023-04-10 22:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126392023-04-10 22:11:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x840| Process Name: C:\Windows\System32\LogonUI.exe
126402023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126412023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126422023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126432023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126442023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126452023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126462023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126472023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126482023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126492023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126502023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126512023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126522023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126532023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126542023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126552023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126562023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126572023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126582023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126592023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126602023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126612023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126622023-04-10 22:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126632023-04-10 22:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126642023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126652023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126662023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126672023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126682023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126692023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126702023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126712023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126722023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126732023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126742023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126752023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126762023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126772023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126782023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126792023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126802023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126812023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126822023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126832023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126842023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126852023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126862023-04-10 22:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126872023-04-10 22:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126882023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126892023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126902023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126912023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126922023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126932023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126942023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126952023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126962023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126972023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
126982023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
126992023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127002023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127012023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127022023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127032023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127042023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127052023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127062023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127072023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127082023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127092023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127102023-04-10 22:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127112023-04-10 22:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127122023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127132023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127142023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127152023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127162023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127172023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127182023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127192023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127202023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127212023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127222023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127232023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127242023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127252023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127262023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127272023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127282023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127292023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127302023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127312023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127322023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127332023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127342023-04-10 22:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127352023-04-10 22:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127362023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127372023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127382023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127392023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127402023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127412023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127422023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127432023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127442023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127452023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127462023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127472023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127482023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127492023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127502023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127512023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127522023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127532023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127542023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127552023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127562023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127572023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127582023-04-10 22:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127592023-04-10 22:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127602023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127612023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127622023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127632023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127642023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127652023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127662023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127672023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127682023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127692023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127702023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127712023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127722023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127732023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127742023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127752023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127762023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127772023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127782023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127792023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127802023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127812023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127822023-04-10 22:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127832023-04-10 22:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127842023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127852023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127862023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127872023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127882023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127892023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127902023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127912023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127922023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127932023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127942023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127952023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127962023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127972023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
127982023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
127992023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128002023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128012023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128022023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128032023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128042023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128052023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128062023-04-10 22:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128072023-04-10 22:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128082023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128092023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128102023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128112023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128122023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128132023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128142023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128152023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128162023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128172023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128182023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128192023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128202023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128212023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128222023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128232023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128242023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128252023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128262023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128272023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128282023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128292023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128302023-04-10 22:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128312023-04-10 22:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128322023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128332023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128342023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128352023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128362023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128372023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128382023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128392023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128402023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128412023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128422023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128432023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128442023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128452023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128462023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128472023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128482023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128492023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128502023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128512023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128522023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128532023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128542023-04-10 22:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128552023-04-10 22:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128562023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128572023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128582023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128592023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128602023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128612023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128622023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128632023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128642023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128652023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128662023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128672023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128682023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128692023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128702023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128712023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128722023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128732023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128742023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128752023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128762023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128772023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128782023-04-10 22:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128792023-04-10 22:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128802023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128812023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128822023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128832023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128842023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128852023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128862023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128872023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128882023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128892023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128902023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128912023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128922023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128932023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128942023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128952023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128962023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
128972023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
128982023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
128992023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129002023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129012023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129022023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129032023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129042023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129052023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129062023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129072023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129082023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129092023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129102023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129112023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129122023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129132023-04-10 22:01:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
129142023-04-10 22:01:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
129152023-04-10 22:01:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
129162023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129172023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129182023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129192023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129202023-04-10 22:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129212023-04-10 22:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129222023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129232023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129242023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129252023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129262023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129272023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129282023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129292023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129302023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129312023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129322023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129332023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129342023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129352023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129362023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129372023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129382023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129392023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129402023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129412023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129422023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129432023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129442023-04-10 22:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129452023-04-10 22:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129462023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129472023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129482023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129492023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129502023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129512023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129522023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129532023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129542023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129552023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129562023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129572023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129582023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129592023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129602023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129612023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129622023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129632023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129642023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129652023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129662023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129672023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129682023-04-10 21:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129692023-04-10 21:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129702023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129712023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129722023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129732023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129742023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129752023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129762023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129772023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129782023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129792023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129802023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129812023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129822023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129832023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129842023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129852023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129862023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129872023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129882023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129892023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129902023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129912023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129922023-04-10 21:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129932023-04-10 21:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129942023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129952023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129962023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129972023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
129982023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
129992023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130002023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130012023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130022023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130032023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130042023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130052023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130062023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130072023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130082023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130092023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130102023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130112023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130122023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130132023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130142023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130152023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130162023-04-10 21:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130172023-04-10 21:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130182023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130192023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130202023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130212023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130222023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130232023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130242023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130252023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130262023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130272023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130282023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130292023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130302023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130312023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130322023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130332023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130342023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130352023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130362023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130372023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130382023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130392023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130402023-04-10 21:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130412023-04-10 21:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130422023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130432023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130442023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130452023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130462023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130472023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130482023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130492023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130502023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130512023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130522023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130532023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130542023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130552023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130562023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130572023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130582023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130592023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130602023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130612023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130622023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130632023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130642023-04-10 21:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130652023-04-10 21:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130662023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130672023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130682023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130692023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130702023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130712023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130722023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130732023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130742023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130752023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130762023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130772023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130782023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130792023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130802023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130812023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130822023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130832023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130842023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130852023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130862023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130872023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130882023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
130892023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
130902023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130912023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130922023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130932023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130942023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130952023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130962023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130972023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130982023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
130992023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131002023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131012023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131022023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131032023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131042023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131052023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131062023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131072023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131082023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131092023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131102023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131112023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131122023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131132023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131142023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131152023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131162023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131172023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131182023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131192023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131202023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131212023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131222023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131232023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131242023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131252023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131262023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131272023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131282023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131292023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131302023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131312023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131322023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131332023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131342023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131352023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131362023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131372023-04-10 21:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
131382023-04-10 21:54:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
131392023-04-10 21:54:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
131402023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131412023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131422023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131432023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131442023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131452023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131462023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131472023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131482023-04-10 21:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131492023-04-10 21:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131502023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131512023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131522023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131532023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131542023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131552023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131562023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131572023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131582023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131592023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131602023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131612023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131622023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131632023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131642023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131652023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131662023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131672023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131682023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131692023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131702023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131712023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131722023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131732023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131742023-04-10 21:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131752023-04-10 21:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131762023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131772023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131782023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131792023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131802023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131812023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131822023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131832023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131842023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131852023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131862023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131872023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131882023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131892023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131902023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131912023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131922023-04-10 21:52:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
131932023-04-10 21:52:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
131942023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131952023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131962023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131972023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
131982023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
131992023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132002023-04-10 21:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132012023-04-10 21:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132022023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132032023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132042023-04-10 21:51:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
132052023-04-10 21:51:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
132062023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132072023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132082023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132092023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132102023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132112023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132122023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132132023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132142023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132152023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132162023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132172023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132182023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132192023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132202023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132212023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132222023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132232023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132242023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132252023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132262023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132272023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132282023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132292023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132302023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132312023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132322023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132332023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132342023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132352023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132362023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132372023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132382023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132392023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132402023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132412023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132422023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132432023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132442023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132452023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132462023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132472023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132482023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132492023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132502023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132512023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132522023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132532023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132542023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132552023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132562023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132572023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132582023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132592023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132602023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132612023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132622023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132632023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132642023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132652023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132662023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132672023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132682023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132692023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132702023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132712023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132722023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132732023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132742023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132752023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132762023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132772023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132782023-04-10 21:51:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
132792023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132802023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132812023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132822023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132832023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132842023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132852023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132862023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132872023-04-10 21:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132882023-04-10 21:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132892023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132902023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132912023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132922023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132932023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132942023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132952023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132962023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132972023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
132982023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
132992023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133002023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133012023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133022023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133032023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133042023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133052023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133062023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133072023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133082023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133092023-04-10 21:50:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
133102023-04-10 21:50:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
133112023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133122023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133132023-04-10 21:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133142023-04-10 21:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133152023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133162023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133172023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133182023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133192023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133202023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133212023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133222023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133232023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133242023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133252023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133262023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133272023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133282023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133292023-04-10 21:49:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
133302023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133312023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133322023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133332023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133342023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133352023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133362023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133372023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133382023-04-10 21:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133392023-04-10 21:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133402023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133412023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133422023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133432023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133442023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133452023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133462023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133472023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133482023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133492023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133502023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133512023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133522023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133532023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133542023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133552023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133562023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133572023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133582023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133592023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133602023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133612023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133622023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133632023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133642023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133652023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133662023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133672023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133682023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133692023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133702023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133712023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133722023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133732023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133742023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133752023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133762023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133772023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133782023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133792023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
133802023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
133812023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133822023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133832023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133842023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133852023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133862023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133872023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133882023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133892023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133902023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133912023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133922023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133932023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133942023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133952023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133962023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133972023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133982023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
133992023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134002023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134012023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134022023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
134032023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
134042023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134052023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134062023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134072023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134082023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134092023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134102023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134112023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134122023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134132023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134142023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134152023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134162023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134172023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134182023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134192023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134202023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134212023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134222023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134232023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134242023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134252023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134262023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134272023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134282023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134292023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134302023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134312023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134322023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134332023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134342023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134352023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134362023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134372023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134382023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134392023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134402023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134412023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134422023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134432023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134442023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134452023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134462023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134472023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134482023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134492023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134502023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134512023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134522023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134532023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134542023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134552023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134562023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134572023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134582023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134592023-04-10 21:48:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
134602023-04-10 21:48:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
134612023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134622023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134632023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134642023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134652023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134662023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134672023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134682023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134692023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134702023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134712023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134722023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134732023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134742023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134752023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134762023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134772023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134782023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134792023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134802023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134812023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134822023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134832023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134842023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134852023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134862023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134872023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134882023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134892023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134902023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134912023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134922023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134932023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134942023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134952023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134962023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134972023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134982023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
134992023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135002023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135012023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135022023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135032023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135042023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135052023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135062023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135072023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135082023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135092023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135102023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135112023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135122023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135132023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135142023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135152023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135162023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135172023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135182023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135192023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135202023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135212023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135222023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135232023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135242023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135252023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135262023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135272023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135282023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135292023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135302023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135312023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135322023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135332023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135342023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135352023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135362023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135372023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135382023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135392023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135402023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135412023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135422023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135432023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135442023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135452023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135462023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135472023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135482023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135492023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135502023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135512023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135522023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135532023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135542023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135552023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135562023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135572023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135582023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135592023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135602023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135612023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135622023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135632023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135642023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135652023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135662023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135672023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135682023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135692023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135702023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135712023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135722023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135732023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135742023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135752023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135762023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135772023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135782023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135792023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135802023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135812023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135822023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135832023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135842023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135852023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135862023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135872023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135882023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135892023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135902023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135912023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135922023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135932023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135942023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135952023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135962023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135972023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135982023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
135992023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136002023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136012023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136022023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136032023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136042023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136052023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136062023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136072023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136082023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136092023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136102023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136112023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136122023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136132023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136142023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136152023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136162023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136172023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136182023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136192023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136202023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136212023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136222023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136232023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136242023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136252023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136262023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136272023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136282023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136292023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136302023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136312023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136322023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136332023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136342023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136352023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136362023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136372023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136382023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136392023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136402023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136412023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136422023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136432023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136442023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
136452023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
136462023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
136472023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
136482023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
136492023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
136502023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
136512023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
136522023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
136532023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
136542023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
136552023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
136562023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
136572023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
136582023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
136592023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
136602023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
136612023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
136622023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136632023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136642023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136652023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136662023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136672023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136682023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136692023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136702023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136712023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136722023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136732023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136742023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136752023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136762023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136772023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136782023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
136792023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136802023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136812023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136822023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136832023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136842023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136852023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136862023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136872023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136882023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136892023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136902023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136912023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136922023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136932023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136942023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136952023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136962023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136972023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136982023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
136992023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137002023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137012023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137022023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137032023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137042023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137052023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137062023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137072023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137082023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137092023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137102023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137112023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137122023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137132023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137142023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137152023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137162023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137172023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137182023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137192023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137202023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137212023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137222023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137232023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137242023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137252023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137262023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137272023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137282023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137292023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137302023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137312023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137322023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137332023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137342023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137352023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137362023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137372023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137382023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137392023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137402023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137412023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137422023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137432023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137442023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137452023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137462023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137472023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137482023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137492023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137502023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137512023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137522023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137532023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137542023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137552023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137562023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137572023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137582023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137592023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137602023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137612023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137622023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137632023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137642023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137652023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137662023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
137672023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137682023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137692023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137702023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137712023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137722023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137732023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137742023-04-10 21:48:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
137752023-04-10 21:48:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
137762023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137772023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137782023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137792023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137802023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137812023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137822023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137832023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
137842023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137852023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
137862023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137872023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
137882023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137892023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
137902023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137912023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
137922023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137932023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
137942023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137952023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
137962023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137972023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
137982023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
137992023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
138002023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
138012023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
138022023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138032023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138042023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138052023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138062023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138072023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138082023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138092023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
138102023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
138112023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138122023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138132023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138142023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138152023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138162023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138172023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138182023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138192023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138202023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138212023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138222023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138232023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138242023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138252023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138262023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138272023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138282023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138292023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138302023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138312023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138322023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138332023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138342023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138352023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138362023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138372023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138382023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
138392023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
138402023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
138412023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
138422023-04-10 21:48:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x52F67B7||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
138432023-04-10 21:48:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x5306FD4||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
138442023-04-10 21:48:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x52F68D4||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
138452023-04-10 21:48:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x53070BB||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
138462023-04-10 21:48:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5306FD4||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
138472023-04-10 21:48:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x53070BB| Linked Logon ID: 0x5306FD4| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
138482023-04-10 21:48:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5306FD4| Linked Logon ID: 0x53070BB| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
138492023-04-10 21:48:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
138502023-04-10 21:48:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
138512023-04-10 21:48:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
138522023-04-10 21:48:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
138532023-04-10 21:48:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x52F67B7||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
138542023-04-10 21:48:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x52F68D4| Linked Logon ID: 0x52F67B7| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
138552023-04-10 21:48:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x52F67B7| Linked Logon ID: 0x52F68D4| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
138562023-04-10 21:48:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
138572023-04-10 21:48:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
138582023-04-10 21:48:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
138592023-04-10 21:48:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
138602023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138612023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138622023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138632023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138642023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138652023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138662023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138672023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138682023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138692023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138702023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138712023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138722023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138732023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138742023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138752023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138762023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138772023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138782023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138792023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138802023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138812023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138822023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138832023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138842023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138852023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138862023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138872023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138882023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138892023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138902023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138912023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138922023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138932023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138942023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138952023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138962023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138972023-04-10 21:48:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
138982023-04-10 21:48:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5f90| Process Name: C:\Windows\System32\LogonUI.exe
138992023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139002023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139012023-04-10 21:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139022023-04-10 21:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139032023-04-10 19:26:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
139042023-04-10 19:26:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
139052023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139062023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139072023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139082023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139092023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139102023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139112023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139122023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139132023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139142023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139152023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139162023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139172023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139182023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139192023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139202023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139212023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139222023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139232023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139242023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139252023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139262023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139272023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139282023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139292023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139302023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139312023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139322023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139332023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139342023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139352023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139362023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139372023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139382023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139392023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139402023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139412023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139422023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139432023-04-10 19:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139442023-04-10 19:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139452023-04-10 19:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139462023-04-10 15:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139472023-04-10 15:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139482023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139492023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139502023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139512023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139522023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139532023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139542023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139552023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139562023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139572023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139582023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139592023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139602023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139612023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139622023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139632023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139642023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139652023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139662023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139672023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139682023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139692023-04-10 15:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
139702023-04-10 15:53:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
139712023-04-10 15:53:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
139722023-04-10 15:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139732023-04-10 15:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139742023-04-10 15:26:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
139752023-04-10 15:26:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
139762023-04-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139772023-04-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139782023-04-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139792023-04-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139802023-04-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139812023-04-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139822023-04-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139832023-04-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139842023-04-10 15:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139852023-04-10 15:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139862023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139872023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139882023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139892023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139902023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139912023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139922023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139932023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139942023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139952023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139962023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139972023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
139982023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
139992023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140002023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140012023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140022023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140032023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140042023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140052023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140062023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140072023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140082023-04-10 15:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140092023-04-10 15:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140102023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140112023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140122023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140132023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140142023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140152023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140162023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140172023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140182023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140192023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140202023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140212023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140222023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140232023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140242023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140252023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140262023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140272023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140282023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140292023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140302023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140312023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140322023-04-10 15:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140332023-04-10 15:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140342023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140352023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140362023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140372023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140382023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140392023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140402023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140412023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140422023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140432023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140442023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140452023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140462023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140472023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140482023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140492023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140502023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140512023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140522023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140532023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140542023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140552023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140562023-04-10 15:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140572023-04-10 15:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140582023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140592023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140602023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140612023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140622023-04-10 15:22:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
140632023-04-10 15:22:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
140642023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140652023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140662023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140672023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140682023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140692023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140702023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140712023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140722023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140732023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140742023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140752023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140762023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140772023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140782023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140792023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140802023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140812023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140822023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140832023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140842023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140852023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140862023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140872023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
140882023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
140892023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140902023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140912023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140922023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140932023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140942023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140952023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140962023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140972023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140982023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
140992023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141002023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141012023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141022023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141032023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141042023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141052023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141062023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141072023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141082023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141092023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141102023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
141112023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
141122023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141132023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141142023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141152023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141162023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141172023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141182023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141192023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141202023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141212023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141222023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141232023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141242023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141252023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141262023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141272023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141282023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141292023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141302023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141312023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141322023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141332023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141342023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141352023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141362023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141372023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141382023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141392023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
141402023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
141412023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141422023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141432023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141442023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141452023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141462023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141472023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141482023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141492023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141502023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141512023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141522023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141532023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141542023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141552023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141562023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141572023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141582023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141592023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141602023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141612023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141622023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141632023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141642023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141652023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141662023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141672023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141682023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141692023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141702023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141712023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141722023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141732023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141742023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141752023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141762023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141772023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141782023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141792023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141802023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141812023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141822023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141832023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141842023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141852023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141862023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141872023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141882023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141892023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141902023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141912023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141922023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141932023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141942023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141952023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141962023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141972023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141982023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
141992023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142002023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142012023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142022023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142032023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142042023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142052023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142062023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142072023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142082023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142092023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142102023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142112023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142122023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
142132023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
142142023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142152023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142162023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142172023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142182023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142192023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142202023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142212023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142222023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142232023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142242023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142252023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142262023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142272023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142282023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142292023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142302023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142312023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142322023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142332023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142342023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142352023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142362023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142372023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142382023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142392023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142402023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142412023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142422023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142432023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142442023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142452023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142462023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142472023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142482023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142492023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142502023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142512023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142522023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142532023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142542023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142552023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142562023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142572023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142582023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142592023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142602023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142612023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142622023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142632023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142642023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142652023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142662023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142672023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142682023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142692023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142702023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142712023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142722023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142732023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142742023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142752023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142762023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142772023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142782023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142792023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142802023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142812023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142822023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142832023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142842023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142852023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142862023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142872023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142882023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142892023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142902023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142912023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142922023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142932023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142942023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142952023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
142962023-04-10 15:22:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
142972023-04-10 15:22:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
142982023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
142992023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143002023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143012023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143022023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143032023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143042023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143052023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143062023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143072023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143082023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143092023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143102023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143112023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143122023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143132023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143142023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143152023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143162023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143172023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143182023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143192023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143202023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143212023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143222023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143232023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143242023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143252023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143262023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143272023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143282023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143292023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143302023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143312023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143322023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143332023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143342023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143352023-04-10 15:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143362023-04-10 15:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143372023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143382023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143392023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143402023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143412023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143422023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143432023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143442023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143452023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143462023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143472023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143482023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143492023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143502023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143512023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143522023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143532023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143542023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143552023-04-10 15:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
143562023-04-10 15:22:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
143572023-04-10 15:22:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
143582023-04-10 15:08:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
143592023-04-10 15:08:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
143602023-04-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143612023-04-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143622023-04-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143632023-04-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143642023-04-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143652023-04-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143662023-04-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143672023-04-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143682023-04-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143692023-04-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143702023-04-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143712023-04-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143722023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143732023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143742023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143752023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143762023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143772023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143782023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143792023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143802023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143812023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143822023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143832023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143842023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143852023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143862023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143872023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143882023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143892023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143902023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143912023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143922023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143932023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143942023-04-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143952023-04-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143962023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143972023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
143982023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
143992023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144002023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144012023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144022023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144032023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144042023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144052023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144062023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144072023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144082023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144092023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144102023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144112023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144122023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144132023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144142023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144152023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144162023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144172023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144182023-04-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144192023-04-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144202023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144212023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144222023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144232023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144242023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144252023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144262023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144272023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144282023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144292023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144302023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144312023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144322023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144332023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144342023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144352023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144362023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144372023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144382023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144392023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144402023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144412023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144422023-04-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144432023-04-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144442023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144452023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144462023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144472023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144482023-04-10 15:03:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
144492023-04-10 15:03:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
144502023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144512023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144522023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144532023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144542023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144552023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144562023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144572023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144582023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144592023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144602023-04-10 15:03:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5f90| Process Name: C:\Windows\System32\LogonUI.exe
144612023-04-10 15:03:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
144622023-04-10 15:03:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
144632023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144642023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144652023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144662023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144672023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144682023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144692023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144702023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144712023-04-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144722023-04-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144732023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144742023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144752023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144762023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144772023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144782023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144792023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144802023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144812023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144822023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144832023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144842023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144852023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144862023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144872023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144882023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144892023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144902023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144912023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144922023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144932023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144942023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144952023-04-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144962023-04-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144972023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
144982023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
144992023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145002023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145012023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145022023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145032023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145042023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145052023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145062023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145072023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145082023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145092023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145102023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145112023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145122023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145132023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145142023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145152023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145162023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145172023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145182023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145192023-04-10 15:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145202023-04-10 15:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145212023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145222023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145232023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145242023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145252023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145262023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145272023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145282023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145292023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145302023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145312023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145322023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145332023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145342023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145352023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145362023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145372023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145382023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145392023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145402023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145412023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145422023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145432023-04-10 15:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145442023-04-10 15:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145452023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145462023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145472023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145482023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145492023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145502023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145512023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145522023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145532023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145542023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145552023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145562023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145572023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145582023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145592023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145602023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145612023-04-10 14:59:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
145622023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145632023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145642023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145652023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145662023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145672023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145682023-04-10 14:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145692023-04-10 14:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145702023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145712023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145722023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145732023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145742023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145752023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145762023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145772023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145782023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145792023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145802023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145812023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145822023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145832023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145842023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145852023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145862023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145872023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145882023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145892023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145902023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145912023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145922023-04-10 14:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145932023-04-10 14:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145942023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145952023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145962023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145972023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
145982023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
145992023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146002023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146012023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146022023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146032023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146042023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146052023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146062023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146072023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146082023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146092023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146102023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146112023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146122023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146132023-04-10 14:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146142023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146152023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146162023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146172023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146182023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146192023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146202023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146212023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146222023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146232023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146242023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146252023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146262023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146272023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146282023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146292023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146302023-04-10 14:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146312023-04-10 14:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146322023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146332023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146342023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146352023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146362023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146372023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146382023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146392023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146402023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146412023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146422023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146432023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146442023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146452023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146462023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146472023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146482023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146492023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146502023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146512023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146522023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146532023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146542023-04-10 14:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146552023-04-10 14:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146562023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146572023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146582023-04-10 14:55:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
146592023-04-10 14:55:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
146602023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146612023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146622023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146632023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146642023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
146652023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
146662023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146672023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146682023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146692023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146702023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146712023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146722023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146732023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146742023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146752023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146762023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146772023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146782023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146792023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146802023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146812023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146822023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146832023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146842023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146852023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146862023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146872023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146882023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146892023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146902023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146912023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146922023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146932023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146942023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146952023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146962023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146972023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146982023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
146992023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147002023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147012023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147022023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147032023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147042023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147052023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147062023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147072023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147082023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147092023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147102023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147112023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147122023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147132023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147142023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147152023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147162023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147172023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147182023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147192023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147202023-04-10 14:55:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147212023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147222023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147232023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147242023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147252023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147262023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147272023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147282023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147292023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147302023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147312023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147322023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147332023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147342023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147352023-04-10 14:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147362023-04-10 14:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147372023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147382023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147392023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147402023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147412023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147422023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147432023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147442023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147452023-04-10 14:54:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
147462023-04-10 14:54:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
147472023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
147482023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
147492023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147502023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147512023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147522023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147532023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147542023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147552023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147562023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147572023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147582023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147592023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147602023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147612023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147622023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147632023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147642023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147652023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147662023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147672023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147682023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147692023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147702023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147712023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147722023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147732023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147742023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147752023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147762023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147772023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147782023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147792023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147802023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147812023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147822023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147832023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147842023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147852023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147862023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147872023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147882023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147892023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147902023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147912023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147922023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147932023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147942023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147952023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147962023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147972023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147982023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
147992023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148002023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148012023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148022023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148032023-04-10 14:54:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148042023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148052023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148062023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148072023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148082023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148092023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148102023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148112023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148122023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148132023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148142023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148152023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148162023-04-10 14:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148172023-04-10 14:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148182023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148192023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148202023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148212023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148222023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148232023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148242023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148252023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148262023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148272023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148282023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148292023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148302023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148312023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148322023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148332023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148342023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148352023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148362023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148372023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148382023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148392023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148402023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148412023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148422023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148432023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148442023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148452023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148462023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148472023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148482023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148492023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148502023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148512023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148522023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148532023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148542023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148552023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148562023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148572023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148582023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148592023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148602023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148612023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148622023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148632023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148642023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148652023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148662023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148672023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148682023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148692023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
148702023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
148712023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148722023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148732023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148742023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148752023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148762023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148772023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148782023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148792023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148802023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148812023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148822023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148832023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148842023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148852023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148862023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148872023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148882023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148892023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148902023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148912023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148922023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148932023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148942023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148952023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148962023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148972023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148982023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
148992023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149002023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149012023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149022023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149032023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149042023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149052023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149062023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149072023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149082023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149092023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149102023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149112023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149122023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149132023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149142023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149152023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149162023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149172023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149182023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149192023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149202023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149212023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149222023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149232023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149242023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149252023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149262023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149272023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149282023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149292023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149302023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149312023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149322023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149332023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149342023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149352023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
149362023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
149372023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149382023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149392023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149402023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149412023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149422023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149432023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149442023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149452023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149462023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149472023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149482023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149492023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149502023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149512023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149522023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149532023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149542023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149552023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149562023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149572023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149582023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
149592023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
149602023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149612023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149622023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149632023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149642023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149652023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149662023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149672023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149682023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149692023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149702023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149712023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149722023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149732023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149742023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149752023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149762023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149772023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149782023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149792023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149802023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149812023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
149822023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
149832023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
149842023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
149852023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149862023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149872023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149882023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149892023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149902023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149912023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149922023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149932023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149942023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149952023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149962023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149972023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149982023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
149992023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150002023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150012023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150022023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150032023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150042023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150052023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150062023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150072023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150082023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150092023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150102023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150112023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150122023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150132023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150142023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150152023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150162023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150172023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150182023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150192023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150202023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150212023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150222023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150232023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150242023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150252023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150262023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150272023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150282023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150292023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150302023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150312023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150322023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150332023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150342023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150352023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150362023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150372023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150382023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150392023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150402023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150412023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150422023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150432023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150442023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150452023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150462023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150472023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150482023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150492023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150502023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150512023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150522023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150532023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150542023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150552023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150562023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150572023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150582023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150592023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150602023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150612023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150622023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150632023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150642023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150652023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150662023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150672023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150682023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150692023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150702023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150712023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150722023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150732023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150742023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150752023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150762023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150772023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150782023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150792023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150802023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150812023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150822023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150832023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150842023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150852023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150862023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150872023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150882023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150892023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150902023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150912023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150922023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150932023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150942023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150952023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150962023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150972023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150982023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
150992023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151002023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151012023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151022023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151032023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151042023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151052023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151062023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151072023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151082023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151092023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151102023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151112023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151122023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151132023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151142023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151152023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151162023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151172023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151182023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151192023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151202023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151212023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151222023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151232023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151242023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151252023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151262023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151272023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151282023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151292023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151302023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151312023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151322023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151332023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151342023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151352023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151362023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151372023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151382023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151392023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151402023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151412023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151422023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151432023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151442023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151452023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151462023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151472023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151482023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151492023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151502023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151512023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151522023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151532023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151542023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151552023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151562023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151572023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151582023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151592023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151602023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151612023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151622023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151632023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151642023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151652023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151662023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151672023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151682023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151692023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151702023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151712023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151722023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151732023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151742023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151752023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151762023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151772023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151782023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151792023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151802023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
151812023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
151822023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151832023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151842023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151852023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151862023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151872023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151882023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151892023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151902023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151912023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151922023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
151932023-04-10 14:53:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x5023A6E||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
151942023-04-10 14:53:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x5024FEA||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
151952023-04-10 14:53:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x5023B24||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
151962023-04-10 14:53:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x50253DC||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
151972023-04-10 14:53:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5024FEA||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
151982023-04-10 14:53:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x50253DC| Linked Logon ID: 0x5024FEA| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
151992023-04-10 14:53:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5024FEA| Linked Logon ID: 0x50253DC| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
152002023-04-10 14:53:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
152012023-04-10 14:53:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
152022023-04-10 14:53:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
152032023-04-10 14:53:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
152042023-04-10 14:53:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5023A6E||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
152052023-04-10 14:53:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5023B24| Linked Logon ID: 0x5023A6E| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
152062023-04-10 14:53:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x5023A6E| Linked Logon ID: 0x5023B24| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
152072023-04-10 14:53:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
152082023-04-10 14:53:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
152092023-04-10 14:53:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
152102023-04-10 14:53:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
152112023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152122023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152132023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152142023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152152023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152162023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152172023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152182023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152192023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152202023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152212023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152222023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152232023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152242023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152252023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152262023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152272023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152282023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152292023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152302023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152312023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152322023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152332023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152342023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152352023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152362023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152372023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152382023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152392023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152402023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152412023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152422023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152432023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152442023-04-10 14:53:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6f94| Process Name: C:\Windows\System32\LogonUI.exe
152452023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152462023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152472023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152482023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152492023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152502023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152512023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152522023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152532023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152542023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152552023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152562023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152572023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152582023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152592023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152602023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152612023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152622023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152632023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152642023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152652023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152662023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152672023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152682023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152692023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152702023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152712023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152722023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152732023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152742023-04-10 14:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152752023-04-10 14:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152762023-04-10 14:53:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
152772023-04-10 14:53:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
152782023-04-10 14:53:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
152792023-04-10 13:37:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
152802023-04-10 13:37:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
152812023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152822023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152832023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152842023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152852023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152862023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152872023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152882023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152892023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152902023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152912023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152922023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152932023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152942023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152952023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152962023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152972023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
152982023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
152992023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153002023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153012023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153022023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153032023-04-10 13:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153042023-04-10 13:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153052023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153062023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153072023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153082023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153092023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153102023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153112023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153122023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153132023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153142023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153152023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153162023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153172023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153182023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153192023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153202023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153212023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153222023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153232023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153242023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153252023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153262023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153272023-04-10 13:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153282023-04-10 13:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153292023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153302023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153312023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153322023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153332023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153342023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153352023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153362023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153372023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153382023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153392023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153402023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153412023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153422023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153432023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153442023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153452023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153462023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153472023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153482023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153492023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153502023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153512023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153522023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153532023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153542023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153552023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153562023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153572023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153582023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153592023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153602023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153612023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153622023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153632023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153642023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153652023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153662023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153672023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153682023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153692023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153702023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153712023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153722023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153732023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153742023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153752023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
153762023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
153772023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153782023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153792023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153802023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153812023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153822023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153832023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153842023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153852023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153862023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153872023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153882023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153892023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153902023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153912023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153922023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153932023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153942023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153952023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153962023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153972023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153982023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
153992023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154002023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154012023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154022023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154032023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154042023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
154052023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
154062023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154072023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154082023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154092023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154102023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154112023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154122023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154132023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154142023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154152023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154162023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154172023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154182023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154192023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154202023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154212023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154222023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154232023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154242023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154252023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154262023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154272023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
154282023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
154292023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154302023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154312023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154322023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154332023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154342023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154352023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154362023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154372023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154382023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154392023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154402023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154412023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154422023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154432023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154442023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154452023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154462023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154472023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154482023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154492023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154502023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154512023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154522023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154532023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154542023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154552023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154562023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154572023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154582023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154592023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154602023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154612023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154622023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154632023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154642023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154652023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154662023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154672023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154682023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154692023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154702023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154712023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154722023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154732023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154742023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154752023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154762023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154772023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154782023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154792023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154802023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154812023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154822023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154832023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154842023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154852023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154862023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154872023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154882023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154892023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154902023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154912023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154922023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154932023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154942023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154952023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154962023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154972023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154982023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
154992023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155002023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155012023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155022023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155032023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155042023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155052023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155062023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155072023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155082023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155092023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155102023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155112023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155122023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155132023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155142023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155152023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155162023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155172023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155182023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155192023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155202023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155212023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155222023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155232023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155242023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155252023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155262023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155272023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155282023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155292023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155302023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155312023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155322023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155332023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155342023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155352023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155362023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155372023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155382023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155392023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155402023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155412023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155422023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155432023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155442023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155452023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155462023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155472023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155482023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155492023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155502023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155512023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155522023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155532023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155542023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155552023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155562023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155572023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155582023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155592023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155602023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155612023-04-10 13:35:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
155622023-04-10 13:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
155632023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155642023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155652023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
155662023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155672023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
155682023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155692023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
155702023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155712023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
155722023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155732023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
155742023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155752023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
155762023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155772023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
155782023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155792023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
155802023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155812023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
155822023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155832023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
155842023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
155852023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
155862023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155872023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155882023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155892023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155902023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155912023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155922023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155932023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155942023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155952023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155962023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155972023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155982023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
155992023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156002023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156012023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156022023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156032023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156042023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156052023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156062023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156072023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156082023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156092023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156102023-04-10 13:35:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
156112023-04-10 13:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156122023-04-10 13:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156132023-04-10 13:35:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
156142023-04-10 13:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
156152023-04-10 13:35:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
156162023-04-10 13:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
156172023-04-10 13:33:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
156182023-04-10 13:33:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
156192023-04-10 13:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156202023-04-10 13:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156212023-04-10 13:33:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6f94| Process Name: C:\Windows\System32\LogonUI.exe
156222023-04-10 13:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156232023-04-10 13:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156242023-04-10 13:33:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
156252023-04-10 13:33:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
156262023-04-10 13:33:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
156272023-04-10 13:33:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
156282023-04-10 13:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156292023-04-10 13:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156302023-04-10 13:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156312023-04-10 13:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156322023-04-10 13:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156332023-04-10 13:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156342023-04-10 13:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156352023-04-10 13:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156362023-04-10 13:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156372023-04-10 13:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156382023-04-10 13:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156392023-04-10 13:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156402023-04-10 13:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156412023-04-10 13:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156422023-04-10 13:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156432023-04-10 13:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156442023-04-10 13:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156452023-04-10 13:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156462023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156472023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156482023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156492023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156502023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156512023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156522023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156532023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156542023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156552023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156562023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156572023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156582023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156592023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156602023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156612023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156622023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156632023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156642023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156652023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156662023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156672023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156682023-04-10 13:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156692023-04-10 13:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156702023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156712023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156722023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156732023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156742023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156752023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156762023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156772023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156782023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156792023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156802023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156812023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156822023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156832023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156842023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156852023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156862023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156872023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156882023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156892023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156902023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156912023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156922023-04-10 13:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156932023-04-10 13:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156942023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156952023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156962023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156972023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
156982023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
156992023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157002023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157012023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157022023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157032023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157042023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157052023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157062023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157072023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157082023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157092023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157102023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157112023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157122023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157132023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157142023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157152023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157162023-04-10 13:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157172023-04-10 13:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157182023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157192023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157202023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157212023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157222023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157232023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157242023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157252023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157262023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157272023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157282023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157292023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157302023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157312023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157322023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157332023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157342023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157352023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157362023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157372023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157382023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157392023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157402023-04-10 13:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157412023-04-10 13:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157422023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157432023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157442023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157452023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157462023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157472023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157482023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157492023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157502023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157512023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157522023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157532023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157542023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157552023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157562023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157572023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157582023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157592023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157602023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157612023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157622023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157632023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157642023-04-10 13:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157652023-04-10 13:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157662023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157672023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157682023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157692023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157702023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157712023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157722023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157732023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157742023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157752023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157762023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157772023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157782023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157792023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157802023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157812023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157822023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157832023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157842023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157852023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157862023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157872023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157882023-04-10 13:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157892023-04-10 13:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157902023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157912023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157922023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157932023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157942023-04-10 13:26:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
157952023-04-10 13:26:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
157962023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157972023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
157982023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
157992023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158002023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158012023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158022023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158032023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158042023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158052023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158062023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158072023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158082023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158092023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158102023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158112023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158122023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158132023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158142023-04-10 13:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158152023-04-10 13:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158162023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158172023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158182023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158192023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158202023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158212023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158222023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158232023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158242023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158252023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158262023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158272023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158282023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158292023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158302023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158312023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158322023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158332023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158342023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158352023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158362023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158372023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158382023-04-10 13:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158392023-04-10 13:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158402023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158412023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158422023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158432023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158442023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158452023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158462023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158472023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158482023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158492023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158502023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158512023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158522023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158532023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158542023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158552023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158562023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158572023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158582023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158592023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158602023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158612023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158622023-04-10 13:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158632023-04-10 13:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158642023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158652023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158662023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158672023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158682023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158692023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158702023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158712023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158722023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158732023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158742023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158752023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158762023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158772023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158782023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158792023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158802023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158812023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158822023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158832023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158842023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158852023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158862023-04-10 13:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158872023-04-10 13:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158882023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158892023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158902023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158912023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158922023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158932023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158942023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158952023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158962023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158972023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
158982023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
158992023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159002023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159012023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159022023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159032023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159042023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159052023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159062023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159072023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159082023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159092023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159102023-04-10 13:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159112023-04-10 13:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159122023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159132023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159142023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159152023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159162023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159172023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159182023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159192023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159202023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159212023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159222023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159232023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159242023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159252023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159262023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159272023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159282023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159292023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159302023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159312023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159322023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159332023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159342023-04-10 13:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159352023-04-10 13:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159362023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159372023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159382023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159392023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159402023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159412023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159422023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159432023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159442023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159452023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159462023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159472023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159482023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159492023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159502023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159512023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159522023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159532023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159542023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159552023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159562023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159572023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159582023-04-10 13:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159592023-04-10 13:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159602023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159612023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159622023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159632023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159642023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159652023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159662023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159672023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159682023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159692023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159702023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159712023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159722023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159732023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159742023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159752023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159762023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159772023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159782023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159792023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159802023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159812023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159822023-04-10 13:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159832023-04-10 13:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159842023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159852023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159862023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159872023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159882023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159892023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159902023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159912023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159922023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159932023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159942023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159952023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159962023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159972023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
159982023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
159992023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160002023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160012023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160022023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160032023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160042023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160052023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160062023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160072023-04-10 13:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160082023-04-10 13:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160092023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160102023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160112023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160122023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160132023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160142023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160152023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160162023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160172023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160182023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160192023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160202023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160212023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160222023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160232023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160242023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160252023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160262023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160272023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160282023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160292023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160302023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160312023-04-10 13:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160322023-04-10 13:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160332023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160342023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160352023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160362023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160372023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160382023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160392023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160402023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160412023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160422023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160432023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160442023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160452023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160462023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160472023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160482023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160492023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160502023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160512023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160522023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160532023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160542023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160552023-04-10 13:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160562023-04-10 13:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160572023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160582023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160592023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160602023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160612023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160622023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160632023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160642023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160652023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160662023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160672023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160682023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160692023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160702023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160712023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160722023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160732023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160742023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160752023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160762023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160772023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160782023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160792023-04-10 13:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160802023-04-10 13:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160812023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160822023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160832023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160842023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160852023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160862023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160872023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160882023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160892023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160902023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160912023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160922023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160932023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160942023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160952023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160962023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160972023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
160982023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
160992023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161002023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161012023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161022023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161032023-04-10 13:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161042023-04-10 13:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161052023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161062023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161072023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161082023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161092023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161102023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161112023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161122023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161132023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161142023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161152023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161162023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161172023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161182023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161192023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161202023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161212023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161222023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161232023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161242023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161252023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_api.application| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161262023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_office.net| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161272023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161282023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161292023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161302023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161312023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161322023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161332023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161342023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161352023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161362023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161372023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161382023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161392023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161402023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161412023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161422023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161432023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161442023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161452023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161462023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161472023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161482023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161492023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161502023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161512023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161522023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161532023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161542023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161552023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161562023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161572023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161582023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161592023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161602023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161612023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161622023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161632023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161642023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161652023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161662023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161672023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161682023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161692023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161702023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161712023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161722023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161732023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161742023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161752023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161762023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161772023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
161782023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
161792023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161802023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161812023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161822023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161832023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161842023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161852023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161862023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161872023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161882023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161892023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161902023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161912023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161922023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161932023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161942023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161952023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161962023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161972023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161982023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
161992023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162002023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162012023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162022023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162032023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162042023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162052023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162062023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162072023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162082023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162092023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162102023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162112023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162122023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162132023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162142023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162152023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162162023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162172023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162182023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162192023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162202023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162212023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162222023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162232023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162242023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162252023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162262023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162272023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162282023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162292023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162302023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162312023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162322023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162332023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162342023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162352023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162362023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162372023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162382023-04-10 13:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162392023-04-10 13:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
162402023-04-10 13:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
162412023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
162422023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
162432023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
162442023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
162452023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162462023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162472023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162482023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162492023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162502023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162512023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162522023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162532023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162542023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162552023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162562023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162572023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162582023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162592023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162602023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162612023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162622023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162632023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162642023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162652023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162662023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162672023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162682023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162692023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162702023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162712023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162722023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162732023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162742023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162752023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162762023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162772023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162782023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162792023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162802023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162812023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162822023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162832023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162842023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162852023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162862023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162872023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162882023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162892023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162902023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162912023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162922023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162932023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162942023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162952023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162962023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
162972023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
162982023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
162992023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163002023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163012023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163022023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163032023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163042023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163052023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163062023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163072023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163082023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163092023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163102023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163112023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163122023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163132023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163142023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163152023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163162023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163172023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163182023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
163192023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
163202023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_office.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
163212023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_aadrm.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
163222023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
163232023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
163242023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
163252023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
163262023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
163272023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163282023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163292023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163302023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163312023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163322023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163332023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163342023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163352023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163362023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163372023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163382023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163392023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163402023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163412023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163422023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163432023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163442023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163452023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163462023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163472023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163482023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163492023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163502023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163512023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163522023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163532023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163542023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163552023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163562023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163572023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163582023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163592023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163602023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163612023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163622023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163632023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163642023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163652023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163662023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163672023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163682023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163692023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163702023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163712023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163722023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163732023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163742023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163752023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163762023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163772023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163782023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163792023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163802023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163812023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163822023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163832023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163842023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163852023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163862023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163872023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163882023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163892023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163902023-04-10 13:12:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
163912023-04-10 13:12:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
163922023-04-10 13:12:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
163932023-04-10 13:12:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
163942023-04-10 13:12:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
163952023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
163962023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
163972023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
163982023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
163992023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164002023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164012023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164022023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164032023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164042023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164052023-04-10 13:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164062023-04-10 13:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164072023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164082023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164092023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164102023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164112023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164122023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164132023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164142023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164152023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164162023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164172023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164182023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164192023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164202023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164212023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164222023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164232023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164242023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164252023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164262023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164272023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164282023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164292023-04-10 13:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164302023-04-10 13:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164312023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164322023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164332023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164342023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164352023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164362023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164372023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164382023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164392023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164402023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164412023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164422023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164432023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164442023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164452023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164462023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164472023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164482023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164492023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164502023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164512023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164522023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164532023-04-10 13:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164542023-04-10 13:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164552023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164562023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164572023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164582023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164592023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164602023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164612023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164622023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164632023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164642023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164652023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164662023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164672023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164682023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164692023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164702023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164712023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164722023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164732023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164742023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164752023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164762023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164772023-04-10 13:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164782023-04-10 13:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164792023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164802023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164812023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164822023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164832023-04-10 13:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
164842023-04-10 13:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
164852023-04-10 13:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
164862023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164872023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164882023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164892023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164902023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164912023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164922023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164932023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164942023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164952023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164962023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164972023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
164982023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
164992023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165002023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165012023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165022023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165032023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165042023-04-10 13:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165052023-04-10 13:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165062023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165072023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165082023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165092023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165102023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165112023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165122023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165132023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165142023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165152023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165162023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165172023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165182023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165192023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165202023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165212023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165222023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165232023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165242023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165252023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165262023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165272023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165282023-04-10 13:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165292023-04-10 13:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165302023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165312023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165322023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165332023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165342023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165352023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165362023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165372023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165382023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165392023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165402023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165412023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165422023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165432023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165442023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165452023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165462023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165472023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165482023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165492023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165502023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165512023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165522023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165532023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165542023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165552023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165562023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165572023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165582023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165592023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165602023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165612023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165622023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165632023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165642023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165652023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165662023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165672023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165682023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165692023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165702023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165712023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
165722023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
165732023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165742023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165752023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165762023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165772023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165782023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165792023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165802023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165812023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165822023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165832023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165842023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165852023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165862023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165872023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165882023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165892023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165902023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165912023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165922023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165932023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165942023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165952023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165962023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165972023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165982023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
165992023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166002023-04-10 13:06:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166012023-04-10 13:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
166022023-04-10 13:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
166032023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166042023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166052023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166062023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166072023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166082023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166092023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166102023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166112023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166122023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166132023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166142023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166152023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166162023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166172023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166182023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166192023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166202023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166212023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166222023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166232023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166242023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166252023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166262023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166272023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166282023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166292023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166302023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166312023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166322023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166332023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166342023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166352023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166362023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166372023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166382023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166392023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166402023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166412023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166422023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166432023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166442023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166452023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166462023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166472023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166482023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166492023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166502023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166512023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166522023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166532023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166542023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166552023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166562023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166572023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166582023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166592023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166602023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166612023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166622023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166632023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166642023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166652023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166662023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166672023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166682023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166692023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166702023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166712023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166722023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166732023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166742023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166752023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166762023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166772023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166782023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166792023-04-10 13:05:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
166802023-04-10 13:05:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
166812023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166822023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166832023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166842023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166852023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166862023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166872023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166882023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166892023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166902023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166912023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166922023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166932023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166942023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166952023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166962023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166972023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166982023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
166992023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167002023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167012023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167022023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167032023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167042023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167052023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167062023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167072023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167082023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167092023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167102023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167112023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167122023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167132023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167142023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167152023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167162023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167172023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167182023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167192023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167202023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167212023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167222023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167232023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167242023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167252023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167262023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167272023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167282023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167292023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167302023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167312023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
167322023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
167332023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167342023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167352023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167362023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167372023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167382023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167392023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167402023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167412023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167422023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167432023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167442023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167452023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167462023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167472023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167482023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167492023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167502023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167512023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167522023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167532023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167542023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167552023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167562023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167572023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167582023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167592023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167602023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167612023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167622023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167632023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167642023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167652023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167662023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167672023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167682023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167692023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167702023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167712023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167722023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167732023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167742023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167752023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167762023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167772023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167782023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167792023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167802023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167812023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167822023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167832023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167842023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167852023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167862023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167872023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167882023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167892023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167902023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167912023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167922023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167932023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167942023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167952023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167962023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167972023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167982023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
167992023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168002023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168012023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168022023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168032023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168042023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168052023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168062023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168072023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168082023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168092023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168102023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168112023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168122023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168132023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168142023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168152023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168162023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168172023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168182023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168192023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168202023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168212023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168222023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168232023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168242023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168252023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168262023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168272023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168282023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168292023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168302023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168312023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168322023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168332023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168342023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168352023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168362023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168372023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168382023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168392023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168402023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168412023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168422023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168432023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168442023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168452023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168462023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168472023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168482023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168492023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168502023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168512023-04-10 13:05:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
168522023-04-10 13:05:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
168532023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168542023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168552023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168562023-04-10 13:05:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
168572023-04-10 13:05:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
168582023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168592023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168602023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168612023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168622023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168632023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168642023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168652023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168662023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168672023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168682023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168692023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168702023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168712023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168722023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168732023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168742023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168752023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168762023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168772023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168782023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168792023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168802023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168812023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168822023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168832023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168842023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168852023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168862023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168872023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168882023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168892023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
168902023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
168912023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
168922023-04-10 13:05:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x4CE6512||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
168932023-04-10 13:05:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x4CE7183||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
168942023-04-10 13:05:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x4CE72BB||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
168952023-04-10 13:05:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x4CE656D||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
168962023-04-10 13:05:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x4CE7183||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
168972023-04-10 13:05:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x4CE72BB| Linked Logon ID: 0x4CE7183| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
168982023-04-10 13:05:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x4CE7183| Linked Logon ID: 0x4CE72BB| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
168992023-04-10 13:05:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
169002023-04-10 13:05:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
169012023-04-10 13:05:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
169022023-04-10 13:05:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
169032023-04-10 13:05:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x4CE6512||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
169042023-04-10 13:05:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x4CE656D| Linked Logon ID: 0x4CE6512| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
169052023-04-10 13:05:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x4CE6512| Linked Logon ID: 0x4CE656D| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
169062023-04-10 13:05:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
169072023-04-10 13:05:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
169082023-04-10 13:05:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
169092023-04-10 13:05:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
169102023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169112023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169122023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169132023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169142023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169152023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169162023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169172023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169182023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169192023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169202023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169212023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169222023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169232023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169242023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169252023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169262023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169272023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169282023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169292023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169302023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169312023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169322023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169332023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169342023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169352023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169362023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169372023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169382023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169392023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169402023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169412023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169422023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169432023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169442023-04-10 13:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169452023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
169462023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
169472023-04-10 13:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
169482023-04-10 13:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
169492023-04-10 12:10:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
169502023-04-10 12:10:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
169512023-04-10 12:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
169522023-04-10 12:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
169532023-04-10 12:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
169542023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169552023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169562023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169572023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169582023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169592023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169602023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169612023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169622023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169632023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169642023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169652023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169662023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169672023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169682023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169692023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169702023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169712023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169722023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169732023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169742023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169752023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169762023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169772023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169782023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169792023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169802023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169812023-04-10 12:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
169822023-04-10 12:10:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
169832023-04-10 12:10:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
169842023-04-10 12:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
169852023-04-10 12:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
169862023-04-10 12:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
169872023-04-10 12:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
169882023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
169892023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
169902023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
169912023-04-10 12:09:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
169922023-04-10 12:09:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
169932023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
169942023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
169952023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
169962023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
169972023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
169982023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
169992023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170002023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170012023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170022023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170032023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170042023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170052023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170062023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170072023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170082023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170092023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170102023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170112023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170122023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170132023-04-10 12:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170142023-04-10 12:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170152023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170162023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170172023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170182023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170192023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170202023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170212023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170222023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170232023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170242023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170252023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170262023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170272023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170282023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170292023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170302023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170312023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170322023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170332023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170342023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170352023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170362023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170372023-04-10 12:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170382023-04-10 12:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170392023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170402023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170412023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170422023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170432023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170442023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170452023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170462023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170472023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170482023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170492023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170502023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170512023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170522023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170532023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170542023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170552023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170562023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170572023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170582023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170592023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170602023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170612023-04-10 12:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170622023-04-10 12:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170632023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170642023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170652023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170662023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170672023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170682023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170692023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170702023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170712023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170722023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170732023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170742023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170752023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170762023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170772023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170782023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170792023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170802023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170812023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170822023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170832023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170842023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170852023-04-10 12:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170862023-04-10 12:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170872023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170882023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170892023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170902023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170912023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170922023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170932023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170942023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170952023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170962023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170972023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
170982023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
170992023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171002023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171012023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171022023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171032023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171042023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171052023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171062023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171072023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171082023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171092023-04-10 12:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171102023-04-10 12:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171112023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171122023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171132023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171142023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171152023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171162023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171172023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171182023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171192023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171202023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171212023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171222023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171232023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171242023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171252023-04-10 12:04:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x6ca8| Process Name: C:\Windows\System32\LogonUI.exe
171262023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171272023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171282023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171292023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171302023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171312023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171322023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171332023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171342023-04-10 12:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171352023-04-10 12:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171362023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171372023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171382023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171392023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171402023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171412023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171422023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171432023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171442023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171452023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171462023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171472023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171482023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171492023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171502023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171512023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171522023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171532023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171542023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171552023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171562023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171572023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171582023-04-10 12:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171592023-04-10 12:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171602023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171612023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171622023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171632023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171642023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171652023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171662023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171672023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171682023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171692023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171702023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171712023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171722023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171732023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171742023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171752023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171762023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171772023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171782023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171792023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171802023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171812023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171822023-04-10 12:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171832023-04-10 12:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171842023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171852023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171862023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171872023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171882023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171892023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171902023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171912023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171922023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171932023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171942023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171952023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171962023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171972023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
171982023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
171992023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172002023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172012023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172022023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172032023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172042023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172052023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172062023-04-10 12:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172072023-04-10 12:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172082023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172092023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172102023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172112023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172122023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172132023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172142023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172152023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172162023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172172023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172182023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172192023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172202023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172212023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172222023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172232023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172242023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172252023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172262023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172272023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172282023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172292023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172302023-04-10 12:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172312023-04-10 12:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172322023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172332023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172342023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172352023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172362023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172372023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172382023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172392023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172402023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172412023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172422023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172432023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172442023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172452023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172462023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172472023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172482023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172492023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172502023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172512023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172522023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172532023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172542023-04-10 11:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172552023-04-10 11:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172562023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172572023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172582023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172592023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172602023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172612023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172622023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172632023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172642023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172652023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172662023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172672023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172682023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172692023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172702023-04-10 11:58:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
172712023-04-10 11:58:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
172722023-04-10 11:58:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
172732023-04-10 11:58:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
172742023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172752023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172762023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172772023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172782023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172792023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172802023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172812023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172822023-04-10 11:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172832023-04-10 11:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172842023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172852023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172862023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172872023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172882023-04-10 11:57:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
172892023-04-10 11:57:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
172902023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172912023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172922023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172932023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172942023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172952023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172962023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172972023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
172982023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
172992023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173002023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173012023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173022023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173032023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173042023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173052023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173062023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173072023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173082023-04-10 11:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173092023-04-10 11:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173102023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173112023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173122023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173132023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173142023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173152023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173162023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173172023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173182023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173192023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173202023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173212023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173222023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173232023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173242023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173252023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173262023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173272023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173282023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173292023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173302023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173312023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173322023-04-10 11:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173332023-04-10 11:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173342023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173352023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173362023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173372023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173382023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173392023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173402023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173412023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173422023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173432023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173442023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173452023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173462023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173472023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173482023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173492023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173502023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173512023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173522023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173532023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173542023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173552023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173562023-04-10 11:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173572023-04-10 11:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173582023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173592023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173602023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173612023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173622023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173632023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173642023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173652023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173662023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173672023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173682023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173692023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173702023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173712023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173722023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173732023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173742023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173752023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173762023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173772023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173782023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173792023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173802023-04-10 11:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173812023-04-10 11:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173822023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173832023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173842023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173852023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173862023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173872023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173882023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173892023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173902023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173912023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173922023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173932023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173942023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173952023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173962023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173972023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
173982023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
173992023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174002023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174012023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174022023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174032023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174042023-04-10 11:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174052023-04-10 11:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174062023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174072023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174082023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174092023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174102023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174112023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174122023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174132023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174142023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174152023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174162023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174172023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174182023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174192023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174202023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174212023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174222023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174232023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174242023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174252023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174262023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174272023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174282023-04-10 11:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174292023-04-10 11:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174302023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174312023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174322023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174332023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174342023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174352023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174362023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174372023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174382023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174392023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174402023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174412023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174422023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174432023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174442023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174452023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174462023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174472023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174482023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174492023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174502023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174512023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174522023-04-10 11:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174532023-04-10 11:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174542023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174552023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174562023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174572023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174582023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174592023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174602023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174612023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174622023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174632023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174642023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174652023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174662023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174672023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174682023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174692023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174702023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174712023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174722023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174732023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174742023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174752023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174762023-04-10 11:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174772023-04-10 11:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174782023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174792023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174802023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174812023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174822023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174832023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174842023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174852023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174862023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174872023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174882023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174892023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174902023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174912023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174922023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174932023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174942023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174952023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174962023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174972023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
174982023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
174992023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175002023-04-10 11:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175012023-04-10 11:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175022023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175032023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175042023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175052023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175062023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175072023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175082023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175092023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175102023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175112023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175122023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175132023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175142023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175152023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175162023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175172023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175182023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175192023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175202023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175212023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175222023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175232023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175242023-04-10 11:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175252023-04-10 11:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175262023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175272023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175282023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175292023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175302023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175312023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175322023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175332023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175342023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175352023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175362023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175372023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175382023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175392023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175402023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175412023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175422023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175432023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175442023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175452023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175462023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175472023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175482023-04-10 11:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175492023-04-10 11:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175502023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175512023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175522023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175532023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175542023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175552023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175562023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175572023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175582023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175592023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175602023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175612023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175622023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175632023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175642023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175652023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175662023-04-10 11:46:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
175672023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175682023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175692023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175702023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175712023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175722023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175732023-04-10 11:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175742023-04-10 11:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175752023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175762023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175772023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175782023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175792023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175802023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175812023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175822023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175832023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175842023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175852023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175862023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175872023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175882023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175892023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
175902023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
175912023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
175922023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
175932023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
175942023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
175952023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
175962023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
175972023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
175982023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
175992023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176002023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176012023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176022023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176032023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176042023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176052023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176062023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176072023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176082023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176092023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176102023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176112023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176122023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176132023-04-10 11:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
176142023-04-10 11:45:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
176152023-04-10 11:45:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
176162023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176172023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176182023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176192023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176202023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176212023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176222023-04-10 11:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176232023-04-10 11:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176242023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176252023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176262023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176272023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176282023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176292023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176302023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176312023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176322023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176332023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176342023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176352023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176362023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176372023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176382023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176392023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176402023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176412023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176422023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176432023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176442023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176452023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176462023-04-10 11:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176472023-04-10 11:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176482023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176492023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176502023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176512023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176522023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176532023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176542023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176552023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176562023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176572023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176582023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176592023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176602023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176612023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176622023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176632023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176642023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176652023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176662023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176672023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176682023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176692023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176702023-04-10 11:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176712023-04-10 11:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176722023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176732023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176742023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176752023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176762023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176772023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176782023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176792023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176802023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176812023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176822023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176832023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176842023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176852023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176862023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176872023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176882023-04-10 11:42:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
176892023-04-10 11:42:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
176902023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176912023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176922023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176932023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176942023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176952023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176962023-04-10 11:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176972023-04-10 11:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
176982023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
176992023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177002023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177012023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177022023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177032023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177042023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177052023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177062023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177072023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177082023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177092023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177102023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177112023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177122023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177132023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177142023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177152023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177162023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177172023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177182023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177192023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177202023-04-10 11:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177212023-04-10 11:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177222023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177232023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177242023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177252023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177262023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177272023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177282023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177292023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177302023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177312023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177322023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177332023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177342023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177352023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177362023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177372023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177382023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177392023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177402023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177412023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177422023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177432023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177442023-04-10 11:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177452023-04-10 11:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177462023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177472023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177482023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177492023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177502023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177512023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177522023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177532023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177542023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177552023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177562023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177572023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177582023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177592023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177602023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177612023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177622023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177632023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177642023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177652023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177662023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177672023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177682023-04-10 11:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177692023-04-10 11:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177702023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177712023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177722023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177732023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177742023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177752023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177762023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177772023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177782023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177792023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177802023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177812023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177822023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177832023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177842023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177852023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177862023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177872023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177882023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177892023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177902023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177912023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177922023-04-10 11:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177932023-04-10 11:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177942023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177952023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177962023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177972023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
177982023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
177992023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178002023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178012023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178022023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178032023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178042023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178052023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178062023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178072023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178082023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178092023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178102023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178112023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178122023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178132023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178142023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178152023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178162023-04-10 11:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178172023-04-10 11:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178182023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178192023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178202023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178212023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178222023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178232023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178242023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178252023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178262023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178272023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178282023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178292023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178302023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178312023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178322023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178332023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178342023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178352023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178362023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178372023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178382023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178392023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178402023-04-10 11:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178412023-04-10 11:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178422023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178432023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178442023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178452023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178462023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178472023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178482023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178492023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178502023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178512023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178522023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178532023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178542023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178552023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178562023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178572023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178582023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178592023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178602023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178612023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178622023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178632023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178642023-04-10 11:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178652023-04-10 11:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178662023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178672023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178682023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178692023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178702023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178712023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178722023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178732023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178742023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178752023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178762023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178772023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178782023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178792023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178802023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178812023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178822023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178832023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178842023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178852023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178862023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178872023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178882023-04-10 11:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178892023-04-10 11:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178902023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178912023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178922023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178932023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178942023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178952023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178962023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178972023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
178982023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
178992023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179002023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179012023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179022023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179032023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179042023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179052023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179062023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179072023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179082023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179092023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179102023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179112023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179122023-04-10 11:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179132023-04-10 11:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179142023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179152023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179162023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179172023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179182023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179192023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179202023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179212023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179222023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179232023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179242023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179252023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179262023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179272023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179282023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179292023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179302023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179312023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179322023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179332023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179342023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179352023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179362023-04-10 11:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179372023-04-10 11:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179382023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179392023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179402023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179412023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179422023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179432023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179442023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179452023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179462023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179472023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179482023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179492023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179502023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179512023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179522023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179532023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179542023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179552023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179562023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179572023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179582023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179592023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179602023-04-10 11:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179612023-04-10 11:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179622023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179632023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179642023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179652023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179662023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179672023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179682023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179692023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179702023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179712023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179722023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179732023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179742023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179752023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179762023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179772023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179782023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179792023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179802023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179812023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179822023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179832023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179842023-04-10 11:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179852023-04-10 11:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179862023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179872023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179882023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179892023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179902023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179912023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179922023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179932023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179942023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179952023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179962023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179972023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
179982023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
179992023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180002023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180012023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180022023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180032023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180042023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180052023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180062023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180072023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180082023-04-10 11:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180092023-04-10 11:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180102023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180112023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180122023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180132023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180142023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180152023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180162023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180172023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180182023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180192023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180202023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180212023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180222023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180232023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180242023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180252023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180262023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180272023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180282023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180292023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180302023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180312023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180322023-04-10 11:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180332023-04-10 11:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180342023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180352023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180362023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180372023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180382023-04-10 11:27:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
180392023-04-10 11:27:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
180402023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180412023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180422023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180432023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180442023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180452023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180462023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180472023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180482023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180492023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180502023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180512023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180522023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180532023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180542023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180552023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180562023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180572023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180582023-04-10 11:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180592023-04-10 11:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180602023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180612023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180622023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180632023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180642023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180652023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180662023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180672023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180682023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180692023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180702023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180712023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180722023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180732023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180742023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180752023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180762023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180772023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180782023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180792023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180802023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180812023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180822023-04-10 11:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180832023-04-10 11:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180842023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180852023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180862023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180872023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180882023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180892023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180902023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180912023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180922023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180932023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180942023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180952023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180962023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180972023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
180982023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
180992023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181002023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181012023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181022023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181032023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181042023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181052023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181062023-04-10 11:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181072023-04-10 11:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181082023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181092023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181102023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181112023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181122023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181132023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181142023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181152023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181162023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181172023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181182023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181192023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181202023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181212023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181222023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181232023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181242023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181252023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181262023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181272023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181282023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181292023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181302023-04-10 11:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181312023-04-10 11:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181322023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181332023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181342023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181352023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181362023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181372023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181382023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181392023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181402023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181412023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181422023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181432023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181442023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181452023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181462023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181472023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181482023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181492023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181502023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181512023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181522023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181532023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181542023-04-10 11:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181552023-04-10 11:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181562023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181572023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181582023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181592023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181602023-04-10 11:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
181612023-04-10 11:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
181622023-04-10 11:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
181632023-04-10 11:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
181642023-04-10 11:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
181652023-04-10 11:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
181662023-04-10 11:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
181672023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181682023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181692023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181702023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181712023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181722023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181732023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181742023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181752023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181762023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181772023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181782023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181792023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181802023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181812023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181822023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181832023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181842023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181852023-04-10 11:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181862023-04-10 11:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181872023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181882023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181892023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181902023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181912023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181922023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181932023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181942023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181952023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181962023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181972023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
181982023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
181992023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182002023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182012023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182022023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182032023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182042023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182052023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182062023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182072023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182082023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182092023-04-10 11:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182102023-04-10 11:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182112023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182122023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182132023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182142023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182152023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182162023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182172023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182182023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182192023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182202023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182212023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182222023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182232023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182242023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182252023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182262023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182272023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182282023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182292023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182302023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182312023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182322023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182332023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182342023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182352023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182362023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182372023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182382023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182392023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182402023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182412023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182422023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182432023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182442023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182452023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182462023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182472023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182482023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182492023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182502023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182512023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182522023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182532023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182542023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182552023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182562023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182572023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182582023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182592023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182602023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182612023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182622023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182632023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182642023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182652023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182662023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182672023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182682023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182692023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182702023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182712023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182722023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182732023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182742023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182752023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182762023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182772023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182782023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182792023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182802023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182812023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182822023-04-10 11:20:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182832023-04-10 11:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
182842023-04-10 11:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
182852023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182862023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182872023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182882023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182892023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182902023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182912023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182922023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182932023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182942023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182952023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182962023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182972023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182982023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
182992023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
183002023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
183012023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
183022023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
183032023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
183042023-04-10 11:19:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
183052023-04-10 11:19:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
183062023-04-10 11:19:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
183072023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183082023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183092023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183102023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183112023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183122023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183132023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183142023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183152023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183162023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183172023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183182023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183192023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183202023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183212023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183222023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183232023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183242023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183252023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183262023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183272023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183282023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183292023-04-10 11:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183302023-04-10 11:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183312023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183322023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183332023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183342023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183352023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183362023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183372023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183382023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183392023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183402023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183412023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183422023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183432023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183442023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183452023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183462023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183472023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183482023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183492023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183502023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183512023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183522023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183532023-04-10 11:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183542023-04-10 11:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183552023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183562023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183572023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183582023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183592023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183602023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183612023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183622023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183632023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183642023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183652023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183662023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183672023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183682023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183692023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183702023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183712023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183722023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183732023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183742023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183752023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183762023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183772023-04-10 11:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183782023-04-10 11:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183792023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183802023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183812023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183822023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183832023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183842023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183852023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183862023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183872023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183882023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183892023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183902023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183912023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183922023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183932023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183942023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183952023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183962023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183972023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
183982023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
183992023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184002023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184012023-04-10 11:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184022023-04-10 11:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184032023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184042023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184052023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184062023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184072023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184082023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184092023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184102023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184112023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184122023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184132023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184142023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184152023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184162023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184172023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184182023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184192023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184202023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184212023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184222023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184232023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184242023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184252023-04-10 11:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184262023-04-10 11:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184272023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184282023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184292023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184302023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184312023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184322023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184332023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184342023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184352023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184362023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184372023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184382023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184392023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184402023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184412023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184422023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184432023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184442023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184452023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184462023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184472023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184482023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184492023-04-10 11:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184502023-04-10 11:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184512023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184522023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184532023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184542023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184552023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184562023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184572023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184582023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184592023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184602023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184612023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184622023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184632023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184642023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184652023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184662023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184672023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184682023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184692023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184702023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184712023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184722023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184732023-04-10 11:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184742023-04-10 11:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184752023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184762023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184772023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184782023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184792023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184802023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184812023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184822023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184832023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184842023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184852023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184862023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184872023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184882023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184892023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184902023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184912023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184922023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184932023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184942023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184952023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184962023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184972023-04-10 11:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
184982023-04-10 11:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
184992023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185002023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185012023-04-10 11:11:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
185022023-04-10 11:11:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
185032023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185042023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185052023-04-10 11:11:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
185062023-04-10 11:11:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
185072023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185082023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185092023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185102023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185112023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185122023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185132023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185142023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185152023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185162023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185172023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185182023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185192023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185202023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185212023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185222023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185232023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185242023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185252023-04-10 11:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185262023-04-10 11:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185272023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185282023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185292023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185302023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185312023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185322023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185332023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185342023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185352023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185362023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185372023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185382023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185392023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185402023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185412023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185422023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185432023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185442023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185452023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185462023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185472023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185482023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185492023-04-10 11:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185502023-04-10 11:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185512023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185522023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185532023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185542023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185552023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185562023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185572023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185582023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185592023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185602023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185612023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185622023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185632023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185642023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185652023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185662023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185672023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185682023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185692023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185702023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185712023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185722023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185732023-04-10 11:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185742023-04-10 11:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185752023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185762023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185772023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185782023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185792023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185802023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185812023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185822023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185832023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185842023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185852023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185862023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185872023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185882023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185892023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185902023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185912023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185922023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185932023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185942023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185952023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185962023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185972023-04-10 11:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
185982023-04-10 11:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
185992023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186002023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186012023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186022023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186032023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186042023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186052023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186062023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186072023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186082023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186092023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186102023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186112023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186122023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186132023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186142023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186152023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186162023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186172023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186182023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186192023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186202023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186212023-04-10 11:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186222023-04-10 11:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186232023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186242023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186252023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186262023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186272023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186282023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186292023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186302023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186312023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186322023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186332023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186342023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186352023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186362023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186372023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186382023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186392023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186402023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186412023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186422023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186432023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186442023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186452023-04-10 11:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186462023-04-10 11:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186472023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186482023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186492023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186502023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186512023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186522023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186532023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186542023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186552023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186562023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186572023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186582023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186592023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186602023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186612023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186622023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186632023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186642023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186652023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186662023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186672023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186682023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186692023-04-10 11:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186702023-04-10 11:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186712023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186722023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186732023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186742023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186752023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186762023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186772023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186782023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186792023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186802023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186812023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186822023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186832023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186842023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186852023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186862023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186872023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186882023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186892023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186902023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186912023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186922023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186932023-04-10 11:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186942023-04-10 11:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186952023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186962023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186972023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
186982023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
186992023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187002023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187012023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187022023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187032023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187042023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187052023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187062023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187072023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187082023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187092023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187102023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187112023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187122023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187132023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187142023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187152023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187162023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187172023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187182023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187192023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187202023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187212023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187222023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187232023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187242023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187252023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187262023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187272023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187282023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187292023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187302023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187312023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187322023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187332023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187342023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187352023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187362023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187372023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187382023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187392023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187402023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187412023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187422023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187432023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187442023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187452023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187462023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187472023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187482023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187492023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187502023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187512023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187522023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187532023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187542023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187552023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187562023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187572023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187582023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187592023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187602023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187612023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187622023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187632023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187642023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187652023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187662023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187672023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187682023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187692023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187702023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187712023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187722023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187732023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187742023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187752023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187762023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187772023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187782023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187792023-04-10 11:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
187802023-04-10 11:03:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
187812023-04-10 11:03:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
187822023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187832023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187842023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187852023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187862023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187872023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187882023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187892023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187902023-04-10 11:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187912023-04-10 11:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187922023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187932023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187942023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187952023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187962023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187972023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
187982023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
187992023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188002023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188012023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188022023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188032023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188042023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188052023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188062023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188072023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188082023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188092023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188102023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188112023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188122023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188132023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188142023-04-10 11:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188152023-04-10 11:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188162023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188172023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188182023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188192023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188202023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188212023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188222023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188232023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188242023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188252023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188262023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188272023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188282023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188292023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188302023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188312023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188322023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188332023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188342023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188352023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188362023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188372023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188382023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188392023-04-10 11:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188402023-04-10 11:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188412023-04-10 11:00:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x48CD0E4||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
188422023-04-10 11:00:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x48CDA4C||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
188432023-04-10 11:00:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x48CD142||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
188442023-04-10 11:00:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x48CDB60||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
188452023-04-10 11:00:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x48CDA4C||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
188462023-04-10 11:00:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x48CDB60| Linked Logon ID: 0x48CDA4C| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
188472023-04-10 11:00:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x48CDA4C| Linked Logon ID: 0x48CDB60| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
188482023-04-10 11:00:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
188492023-04-10 11:00:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
188502023-04-10 11:00:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
188512023-04-10 11:00:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
188522023-04-10 11:00:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x48CD0E4||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
188532023-04-10 11:00:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x48CD142| Linked Logon ID: 0x48CD0E4| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
188542023-04-10 11:00:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x48CD0E4| Linked Logon ID: 0x48CD142| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
188552023-04-10 11:00:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
188562023-04-10 11:00:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
188572023-04-10 11:00:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
188582023-04-10 11:00:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
188592023-04-10 11:00:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
188602023-04-10 11:00:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
188612023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188622023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188632023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188642023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188652023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188662023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188672023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188682023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188692023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188702023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188712023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188722023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188732023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188742023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188752023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188762023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188772023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188782023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188792023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188802023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188812023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188822023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188832023-04-10 11:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188842023-04-10 11:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188852023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188862023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188872023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188882023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188892023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188902023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188912023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188922023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188932023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188942023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188952023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188962023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188972023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
188982023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
188992023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189002023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189012023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189022023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189032023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189042023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189052023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189062023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189072023-04-10 10:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189082023-04-10 10:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189092023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189102023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189112023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189122023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189132023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189142023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189152023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189162023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189172023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189182023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189192023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189202023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189212023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189222023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189232023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189242023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189252023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189262023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189272023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189282023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189292023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189302023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189312023-04-10 10:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189322023-04-10 10:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189332023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189342023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189352023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189362023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189372023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189382023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189392023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189402023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189412023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189422023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189432023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189442023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189452023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189462023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189472023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189482023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189492023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189502023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189512023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189522023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189532023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189542023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189552023-04-10 10:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189562023-04-10 10:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189572023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189582023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189592023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189602023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189612023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189622023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189632023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189642023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189652023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189662023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189672023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189682023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189692023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189702023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189712023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189722023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189732023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189742023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189752023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189762023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189772023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189782023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189792023-04-10 10:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189802023-04-10 10:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189812023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189822023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189832023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189842023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189852023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189862023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189872023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189882023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189892023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189902023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189912023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189922023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189932023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189942023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189952023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189962023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189972023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
189982023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
189992023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190002023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190012023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190022023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190032023-04-10 10:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190042023-04-10 10:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190052023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190062023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190072023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190082023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190092023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190102023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190112023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190122023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190132023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190142023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190152023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190162023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190172023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190182023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190192023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190202023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190212023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190222023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190232023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190242023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190252023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190262023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190272023-04-10 10:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190282023-04-10 10:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190292023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190302023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190312023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190322023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190332023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190342023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190352023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190362023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190372023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190382023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190392023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190402023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190412023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190422023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190432023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190442023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190452023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190462023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190472023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190482023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190492023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190502023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190512023-04-10 10:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190522023-04-10 10:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190532023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190542023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190552023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190562023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190572023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190582023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190592023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190602023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190612023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190622023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190632023-04-10 10:52:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
190642023-04-10 10:52:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
190652023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190662023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190672023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190682023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190692023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190702023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190712023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190722023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190732023-04-10 10:52:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
190742023-04-10 10:52:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
190752023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190762023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190772023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190782023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190792023-04-10 10:52:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5b08| Process Name: C:\Windows\System32\LogonUI.exe
190802023-04-10 10:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190812023-04-10 10:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190822023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190832023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190842023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190852023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190862023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190872023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190882023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190892023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190902023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190912023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190922023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190932023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190942023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190952023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190962023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190972023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
190982023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
190992023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191002023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191012023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191022023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191032023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191042023-04-10 10:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191052023-04-10 10:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191062023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191072023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191082023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191092023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191102023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191112023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191122023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191132023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191142023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191152023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191162023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191172023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191182023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191192023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191202023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191212023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191222023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191232023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191242023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191252023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191262023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191272023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191282023-04-10 10:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191292023-04-10 10:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191302023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191312023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191322023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191332023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191342023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191352023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191362023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191372023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191382023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191392023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191402023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191412023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191422023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191432023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191442023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191452023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191462023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191472023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191482023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191492023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191502023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191512023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191522023-04-10 10:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191532023-04-10 10:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191542023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191552023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191562023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191572023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191582023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191592023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191602023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191612023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191622023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191632023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191642023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191652023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191662023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191672023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191682023-04-10 10:48:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
191692023-04-10 10:48:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
191702023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191712023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191722023-04-10 10:48:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
191732023-04-10 10:48:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
191742023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191752023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191762023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191772023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191782023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191792023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191802023-04-10 10:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191812023-04-10 10:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191822023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191832023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191842023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191852023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191862023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191872023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191882023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191892023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191902023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191912023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191922023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191932023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191942023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191952023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191962023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191972023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
191982023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
191992023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192002023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192012023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192022023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192032023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192042023-04-10 10:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192052023-04-10 10:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192062023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192072023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192082023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192092023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192102023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192112023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192122023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192132023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192142023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192152023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192162023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192172023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192182023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192192023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192202023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192212023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192222023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192232023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192242023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192252023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192262023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192272023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192282023-04-10 10:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192292023-04-10 10:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192302023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192312023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192322023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192332023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192342023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192352023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192362023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192372023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192382023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192392023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192402023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192412023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192422023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192432023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192442023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192452023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192462023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192472023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192482023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192492023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192502023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192512023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192522023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192532023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192542023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192552023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192562023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192572023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192582023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192592023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192602023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192612023-04-10 10:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
192622023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192632023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192642023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192652023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192662023-04-10 10:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192672023-04-10 10:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192682023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192692023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192702023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192712023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192722023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192732023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192742023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192752023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192762023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192772023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192782023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192792023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192802023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192812023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192822023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192832023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192842023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192852023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192862023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192872023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192882023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192892023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192902023-04-10 10:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192912023-04-10 10:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192922023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192932023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192942023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192952023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192962023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192972023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
192982023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
192992023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
193002023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
193012023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
193022023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
193032023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
193042023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
193052023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
193062023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
193072023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
193082023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
193092023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
193102023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193112023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193122023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193132023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193142023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193152023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193162023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193172023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193182023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193192023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193202023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193212023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193222023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193232023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193242023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193252023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193262023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193272023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193282023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193292023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193302023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193312023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193322023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193332023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193342023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193352023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193362023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193372023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193382023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193392023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193402023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193412023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193422023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193432023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193442023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193452023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193462023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193472023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193482023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193492023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193502023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193512023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193522023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193532023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193542023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193552023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193562023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193572023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193582023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193592023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193602023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193612023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193622023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193632023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193642023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193652023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193662023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193672023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193682023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193692023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193702023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193712023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193722023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193732023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193742023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193752023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193762023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193772023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193782023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193792023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193802023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193812023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193822023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193832023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193842023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193852023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193862023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193872023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193882023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193892023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193902023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193912023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193922023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193932023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193942023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193952023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193962023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193972023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193982023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
193992023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194002023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194012023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194022023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194032023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194042023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194052023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194062023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194072023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194082023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194092023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194102023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194112023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194122023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194132023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194142023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194152023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194162023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194172023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194182023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194192023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194202023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194212023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194222023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194232023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194242023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194252023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194262023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194272023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194282023-04-10 10:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
194292023-04-10 10:43:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
194302023-04-10 10:43:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
194312023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194322023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194332023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194342023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194352023-04-10 10:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194362023-04-10 10:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194372023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194382023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194392023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194402023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194412023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194422023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194432023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194442023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194452023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194462023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194472023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194482023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194492023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194502023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194512023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194522023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194532023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194542023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194552023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194562023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194572023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194582023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194592023-04-10 10:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194602023-04-10 10:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194612023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194622023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194632023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194642023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194652023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194662023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194672023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194682023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194692023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194702023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194712023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194722023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194732023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194742023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194752023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194762023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194772023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194782023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194792023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194802023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194812023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194822023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194832023-04-10 10:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194842023-04-10 10:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194852023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194862023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194872023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194882023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194892023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194902023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194912023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194922023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194932023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194942023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194952023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194962023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194972023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
194982023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
194992023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195002023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195012023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195022023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195032023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195042023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195052023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195062023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195072023-04-10 10:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195082023-04-10 10:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195092023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195102023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195112023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195122023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195132023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195142023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195152023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195162023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195172023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195182023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195192023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195202023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195212023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195222023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195232023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195242023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195252023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195262023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195272023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195282023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195292023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195302023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195312023-04-10 10:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195322023-04-10 10:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195332023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195342023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195352023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195362023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195372023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195382023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195392023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195402023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195412023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195422023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195432023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195442023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195452023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195462023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195472023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195482023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195492023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195502023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195512023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195522023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195532023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195542023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195552023-04-10 10:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195562023-04-10 10:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195572023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195582023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195592023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195602023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195612023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195622023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195632023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195642023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195652023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195662023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195672023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195682023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195692023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195702023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195712023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195722023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195732023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195742023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195752023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195762023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195772023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195782023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195792023-04-10 10:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195802023-04-10 10:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195812023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195822023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195832023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195842023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195852023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195862023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195872023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195882023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195892023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195902023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195912023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195922023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195932023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195942023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195952023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195962023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195972023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
195982023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
195992023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196002023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196012023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196022023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196032023-04-10 10:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196042023-04-10 10:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196052023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196062023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196072023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196082023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196092023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196102023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196112023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196122023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196132023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196142023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196152023-04-10 10:35:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
196162023-04-10 10:35:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
196172023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196182023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196192023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196202023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196212023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196222023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196232023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196242023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196252023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196262023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196272023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196282023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196292023-04-10 10:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196302023-04-10 10:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196312023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196322023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196332023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196342023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196352023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196362023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196372023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196382023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196392023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196402023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196412023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196422023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196432023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196442023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196452023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196462023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196472023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196482023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196492023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196502023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196512023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196522023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196532023-04-10 10:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196542023-04-10 10:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196552023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196562023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196572023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196582023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196592023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196602023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196612023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196622023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196632023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196642023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196652023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196662023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196672023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196682023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196692023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196702023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196712023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196722023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196732023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196742023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196752023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196762023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196772023-04-10 10:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196782023-04-10 10:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196792023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196802023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196812023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196822023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196832023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196842023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196852023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196862023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196872023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196882023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196892023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196902023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196912023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196922023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196932023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196942023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196952023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196962023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196972023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
196982023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
196992023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197002023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197012023-04-10 10:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197022023-04-10 10:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197032023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197042023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197052023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197062023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197072023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197082023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197092023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197102023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197112023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197122023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197132023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197142023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197152023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197162023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197172023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197182023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197192023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197202023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197212023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197222023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197232023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197242023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197252023-04-10 10:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197262023-04-10 10:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197272023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197282023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197292023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197302023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197312023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197322023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197332023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197342023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197352023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197362023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197372023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197382023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197392023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197402023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197412023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197422023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197432023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197442023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197452023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197462023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197472023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197482023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197492023-04-10 10:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197502023-04-10 10:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197512023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197522023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197532023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197542023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197552023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197562023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197572023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197582023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197592023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197602023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197612023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197622023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197632023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197642023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197652023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197662023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197672023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197682023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197692023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197702023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197712023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197722023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197732023-04-10 10:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197742023-04-10 10:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197752023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197762023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197772023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197782023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197792023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197802023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197812023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197822023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197832023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197842023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197852023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197862023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197872023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197882023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197892023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197902023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197912023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197922023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197932023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197942023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197952023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197962023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197972023-04-10 10:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
197982023-04-10 10:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
197992023-04-10 10:27:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
198002023-04-10 10:27:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
198012023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198022023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198032023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198042023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198052023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198062023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198072023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198082023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198092023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198102023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198112023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198122023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198132023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198142023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198152023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198162023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198172023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198182023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198192023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198202023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198212023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198222023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198232023-04-10 10:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198242023-04-10 10:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198252023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198262023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198272023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198282023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198292023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198302023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198312023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198322023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198332023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198342023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198352023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198362023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198372023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198382023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198392023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198402023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198412023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198422023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198432023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198442023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198452023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198462023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198472023-04-10 10:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198482023-04-10 10:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198492023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198502023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198512023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198522023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198532023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198542023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198552023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198562023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198572023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198582023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198592023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198602023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198612023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198622023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198632023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198642023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198652023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198662023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198672023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198682023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198692023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198702023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198712023-04-10 10:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198722023-04-10 10:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198732023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198742023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198752023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198762023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198772023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198782023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198792023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198802023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198812023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198822023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198832023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198842023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198852023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198862023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198872023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198882023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198892023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198902023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198912023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198922023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198932023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198942023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198952023-04-10 10:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198962023-04-10 10:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198972023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
198982023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
198992023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199002023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199012023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199022023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199032023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199042023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199052023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199062023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199072023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199082023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199092023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199102023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199112023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199122023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199132023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199142023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199152023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199162023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199172023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199182023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199192023-04-10 10:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199202023-04-10 10:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199212023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199222023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199232023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199242023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199252023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199262023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199272023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
199282023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
199292023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199302023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199312023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199322023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199332023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199342023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199352023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199362023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199372023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199382023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199392023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199402023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199412023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199422023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199432023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199442023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199452023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199462023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199472023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199482023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199492023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199502023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199512023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199522023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199532023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199542023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199552023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199562023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199572023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199582023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199592023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199602023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199612023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199622023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199632023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199642023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199652023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199662023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199672023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199682023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199692023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199702023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199712023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199722023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199732023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199742023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199752023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199762023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199772023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199782023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199792023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199802023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199812023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199822023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199832023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199842023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199852023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199862023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199872023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199882023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199892023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199902023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199912023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199922023-04-10 10:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
199932023-04-10 10:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5600| Process Name: C:\Windows\System32\taskhostw.exe
199942023-04-10 10:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5600| Process Name: C:\Windows\System32\taskhostw.exe
199952023-04-10 10:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5600| Process Name: C:\Windows\System32\taskhostw.exe
199962023-04-10 10:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5600| Process Name: C:\Windows\System32\taskhostw.exe
199972023-04-10 10:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5600| Process Name: C:\Windows\System32\taskhostw.exe
199982023-04-10 10:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5600| Process Name: C:\Windows\System32\taskhostw.exe
199992023-04-10 10:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5600| Process Name: C:\Windows\System32\taskhostw.exe
200002023-04-10 10:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5600| Process Name: C:\Windows\System32\taskhostw.exe
200012023-04-10 10:22:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
200022023-04-10 10:22:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
200032023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200042023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200052023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200062023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200072023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200082023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200092023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200102023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200112023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200122023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200132023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200142023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200152023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200162023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200172023-04-10 10:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200182023-04-10 10:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200192023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200202023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200212023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200222023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200232023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200242023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200252023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200262023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200272023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200282023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200292023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200302023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200312023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200322023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200332023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200342023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200352023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200362023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200372023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200382023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200392023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200402023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200412023-04-10 10:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200422023-04-10 10:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200432023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200442023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200452023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200462023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200472023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200482023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200492023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200502023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200512023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200522023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200532023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200542023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200552023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200562023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200572023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200582023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200592023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200602023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200612023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200622023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200632023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200642023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200652023-04-10 10:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200662023-04-10 10:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200672023-04-10 10:19:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
200682023-04-10 10:19:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
200692023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200702023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200712023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200722023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200732023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200742023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200752023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200762023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200772023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200782023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200792023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200802023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200812023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200822023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200832023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200842023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200852023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200862023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200872023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200882023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200892023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200902023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200912023-04-10 10:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200922023-04-10 10:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200932023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200942023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200952023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200962023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200972023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
200982023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
200992023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201002023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201012023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201022023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201032023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201042023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201052023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201062023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201072023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201082023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201092023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201102023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201112023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201122023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201132023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201142023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201152023-04-10 10:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201162023-04-10 10:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201172023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201182023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201192023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201202023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201212023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201222023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201232023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201242023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201252023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201262023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201272023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201282023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201292023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201302023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201312023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201322023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201332023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201342023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201352023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201362023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201372023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201382023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201392023-04-10 10:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201402023-04-10 10:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201412023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201422023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201432023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201442023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201452023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201462023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201472023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201482023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201492023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201502023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201512023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201522023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201532023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201542023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201552023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201562023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201572023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201582023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201592023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201602023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201612023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201622023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201632023-04-10 10:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201642023-04-10 10:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201652023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201662023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201672023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201682023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201692023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201702023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201712023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201722023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201732023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201742023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201752023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201762023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201772023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201782023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201792023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201802023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201812023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201822023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201832023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201842023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201852023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201862023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201872023-04-10 10:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201882023-04-10 10:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201892023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201902023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201912023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201922023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201932023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201942023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201952023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201962023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201972023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
201982023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
201992023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202002023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202012023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202022023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202032023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202042023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202052023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202062023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202072023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202082023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202092023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202102023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202112023-04-10 10:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202122023-04-10 10:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202132023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202142023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202152023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202162023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202172023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202182023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202192023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202202023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202212023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202222023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202232023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202242023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202252023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202262023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202272023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202282023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202292023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202302023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202312023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202322023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202332023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202342023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202352023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202362023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202372023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202382023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202392023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202402023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202412023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202422023-04-10 10:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202432023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202442023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202452023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202462023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202472023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202482023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202492023-04-10 10:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202502023-04-10 10:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202512023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202522023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202532023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202542023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202552023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202562023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202572023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202582023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202592023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202602023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202612023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202622023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202632023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202642023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202652023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202662023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202672023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202682023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202692023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202702023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202712023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202722023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202732023-04-10 10:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202742023-04-10 10:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202752023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202762023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202772023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202782023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202792023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202802023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202812023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202822023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202832023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202842023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202852023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202862023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202872023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
202882023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
202892023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202902023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202912023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202922023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202932023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202942023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202952023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202962023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202972023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202982023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
202992023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203002023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203012023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203022023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203032023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203042023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203052023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203062023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203072023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203082023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203092023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203102023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203112023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203122023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203132023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203142023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203152023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203162023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203172023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203182023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203192023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203202023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203212023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203222023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203232023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203242023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203252023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203262023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203272023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203282023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203292023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203302023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203312023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203322023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203332023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203342023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203352023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203362023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203372023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203382023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203392023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203402023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203412023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203422023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203432023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203442023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203452023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203462023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203472023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203482023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203492023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203502023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203512023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203522023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203532023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203542023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203552023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203562023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203572023-04-10 10:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203582023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203592023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203602023-04-10 10:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203612023-04-10 10:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203622023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203632023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203642023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203652023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203662023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203672023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203682023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203692023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203702023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203712023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203722023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203732023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203742023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203752023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203762023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203772023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203782023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203792023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203802023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
203812023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
203822023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203832023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203842023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203852023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203862023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203872023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203882023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203892023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203902023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203912023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203922023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203932023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203942023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203952023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203962023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203972023-04-10 10:10:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
203982023-04-10 10:10:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
203992023-04-10 10:10:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
204002023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204012023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204022023-04-10 10:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204032023-04-10 10:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204042023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204052023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204062023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204072023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204082023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204092023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204102023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204112023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204122023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204132023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204142023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204152023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204162023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204172023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204182023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204192023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204202023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204212023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204222023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204232023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204242023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204252023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204262023-04-10 10:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204272023-04-10 10:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204282023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204292023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204302023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204312023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204322023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204332023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204342023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204352023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204362023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204372023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204382023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204392023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204402023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204412023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204422023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204432023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204442023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204452023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204462023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204472023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204482023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204492023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204502023-04-10 10:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204512023-04-10 10:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204522023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204532023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204542023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204552023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204562023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204572023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204582023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204592023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204602023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204612023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204622023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204632023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204642023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204652023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204662023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204672023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204682023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204692023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204702023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204712023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204722023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204732023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204742023-04-10 10:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204752023-04-10 10:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204762023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204772023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204782023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204792023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204802023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204812023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204822023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204832023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204842023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204852023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204862023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204872023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204882023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204892023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204902023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204912023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204922023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204932023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204942023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204952023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204962023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204972023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
204982023-04-10 10:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
204992023-04-10 10:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205002023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205012023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205022023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205032023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205042023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205052023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205062023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205072023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205082023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205092023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205102023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205112023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205122023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205132023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205142023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205152023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205162023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205172023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205182023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205192023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205202023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205212023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205222023-04-10 10:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205232023-04-10 10:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205242023-04-10 10:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205252023-04-10 10:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205262023-04-10 10:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205272023-04-10 10:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205282023-04-10 10:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205292023-04-10 10:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205302023-04-10 10:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205312023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205322023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205332023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205342023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205352023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205362023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205372023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205382023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205392023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205402023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205412023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205422023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205432023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205442023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205452023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205462023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205472023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205482023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205492023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205502023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205512023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205522023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205532023-04-10 10:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205542023-04-10 10:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205552023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205562023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205572023-04-10 10:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205582023-04-10 10:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205592023-04-10 10:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205602023-04-10 10:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205612023-04-10 10:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205622023-04-10 10:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205632023-04-10 10:03:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205642023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205652023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205662023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205672023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205682023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205692023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205702023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205712023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205722023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205732023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205742023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205752023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205762023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205772023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205782023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205792023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205802023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205812023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205822023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205832023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205842023-04-10 10:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205852023-04-10 10:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205862023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205872023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205882023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205892023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205902023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205912023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205922023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
205932023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
205942023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205952023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205962023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205972023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205982023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
205992023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206002023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206012023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206022023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206032023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206042023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206052023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206062023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206072023-04-10 10:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206082023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206092023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206102023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206112023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206122023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206132023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206142023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206152023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206162023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206172023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206182023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206192023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206202023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206212023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206222023-04-10 10:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206232023-04-10 10:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206242023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206252023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206262023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206272023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206282023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206292023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206302023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206312023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206322023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206332023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206342023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206352023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206362023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206372023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206382023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206392023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206402023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206412023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206422023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206432023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206442023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206452023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206462023-04-10 10:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206472023-04-10 10:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206482023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206492023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206502023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206512023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206522023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206532023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206542023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206552023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206562023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206572023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206582023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206592023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206602023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206612023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206622023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206632023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206642023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206652023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206662023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206672023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206682023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206692023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206702023-04-10 10:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206712023-04-10 10:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206722023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206732023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206742023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206752023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206762023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206772023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206782023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206792023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206802023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206812023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206822023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206832023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206842023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206852023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206862023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206872023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206882023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206892023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206902023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
206912023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
206922023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206932023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206942023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206952023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206962023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206972023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206982023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
206992023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207002023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207012023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207022023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207032023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207042023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207052023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207062023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207072023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207082023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207092023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207102023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207112023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207122023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207132023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207142023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207152023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207162023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207172023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207182023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207192023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207202023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207212023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207222023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207232023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207242023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207252023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207262023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207272023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207282023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207292023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207302023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207312023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207322023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207332023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207342023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207352023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207362023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207372023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207382023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207392023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207402023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207412023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207422023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207432023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207442023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207452023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207462023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207472023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207482023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207492023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207502023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207512023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207522023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207532023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207542023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207552023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207562023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207572023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207582023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207592023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207602023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207612023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207622023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207632023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207642023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207652023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207662023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207672023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207682023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207692023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207702023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207712023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207722023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207732023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207742023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207752023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207762023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207772023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207782023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207792023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207802023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207812023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207822023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207832023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207842023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207852023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207862023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207872023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207882023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207892023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207902023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207912023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207922023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207932023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207942023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207952023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207962023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207972023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207982023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
207992023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208002023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208012023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208022023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208032023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208042023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208052023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208062023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208072023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208082023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208092023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208102023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208112023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208122023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208132023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208142023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208152023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208162023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208172023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208182023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208192023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208202023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208212023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208222023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208232023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208242023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208252023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208262023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208272023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208282023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208292023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208302023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208312023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208322023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208332023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208342023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208352023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208362023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208372023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208382023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208392023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208402023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208412023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208422023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208432023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208442023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208452023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208462023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208472023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208482023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208492023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208502023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208512023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208522023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208532023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208542023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208552023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208562023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208572023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208582023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208592023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208602023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208612023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208622023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208632023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208642023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208652023-04-10 09:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
208662023-04-10 09:59:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
208672023-04-10 09:59:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
208682023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208692023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208702023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208712023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208722023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208732023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208742023-04-10 09:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208752023-04-10 09:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208762023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208772023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208782023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208792023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208802023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208812023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208822023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208832023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208842023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208852023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208862023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208872023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208882023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208892023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208902023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208912023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208922023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208932023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208942023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208952023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208962023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208972023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
208982023-04-10 09:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
208992023-04-10 09:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209002023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209012023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209022023-04-10 09:57:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
209032023-04-10 09:57:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
209042023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209052023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209062023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209072023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209082023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209092023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209102023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209112023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209122023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209132023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209142023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209152023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209162023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209172023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209182023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209192023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209202023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209212023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209222023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209232023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209242023-04-10 09:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209252023-04-10 09:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209262023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209272023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209282023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209292023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209302023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209312023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209322023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209332023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209342023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209352023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209362023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209372023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209382023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209392023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209402023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209412023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209422023-04-10 09:56:00Microsoft-Windows-Security-Auditing4799Security Group ManagementA security-enabled local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Group:| Security ID: BUILTIN\Administrators| Group Name: Administrators| Group Domain: Builtin||Process Information:| Process ID: 0x5e78| Process Name: C:\Windows\System32\svchost.exe
209432023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209442023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209452023-04-10 09:56:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
209462023-04-10 09:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
209472023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209482023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209492023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209502023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209512023-04-10 09:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209522023-04-10 09:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209532023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209542023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209552023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209562023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209572023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209582023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209592023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209602023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209612023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209622023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209632023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209642023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209652023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209662023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209672023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209682023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209692023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209702023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209712023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209722023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209732023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209742023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209752023-04-10 09:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209762023-04-10 09:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209772023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209782023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209792023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209802023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209812023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209822023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209832023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209842023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209852023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209862023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209872023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209882023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209892023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209902023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209912023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209922023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209932023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209942023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209952023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209962023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209972023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
209982023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
209992023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210002023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210012023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210022023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210032023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210042023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210052023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210062023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210072023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210082023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210092023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210102023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210112023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210122023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210132023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210142023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210152023-04-10 09:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210162023-04-10 09:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210172023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210182023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210192023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210202023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210212023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210222023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210232023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210242023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210252023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210262023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210272023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210282023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210292023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210302023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210312023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210322023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210332023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210342023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210352023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210362023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210372023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210382023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210392023-04-10 09:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210402023-04-10 09:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210412023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210422023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210432023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210442023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210452023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210462023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210472023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210482023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210492023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210502023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210512023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210522023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210532023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210542023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210552023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210562023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210572023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210582023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210592023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210602023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210612023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210622023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210632023-04-10 09:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210642023-04-10 09:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210652023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210662023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210672023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210682023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210692023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210702023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210712023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210722023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210732023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210742023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210752023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210762023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210772023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210782023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210792023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210802023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210812023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210822023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210832023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210842023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210852023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210862023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210872023-04-10 09:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210882023-04-10 09:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210892023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210902023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210912023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210922023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210932023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210942023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210952023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210962023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210972023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
210982023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
210992023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211002023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211012023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211022023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211032023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211042023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211052023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211062023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211072023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211082023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211092023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211102023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211112023-04-10 09:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211122023-04-10 09:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211132023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211142023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211152023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211162023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211172023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211182023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211192023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211202023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211212023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211222023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211232023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211242023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211252023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211262023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211272023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211282023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211292023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211302023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211312023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211322023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211332023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211342023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211352023-04-10 09:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211362023-04-10 09:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211372023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211382023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211392023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211402023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211412023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211422023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211432023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211442023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211452023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211462023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211472023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211482023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211492023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211502023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211512023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211522023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211532023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211542023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211552023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211562023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211572023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211582023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211592023-04-10 09:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211602023-04-10 09:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211612023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211622023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211632023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211642023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211652023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211662023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211672023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211682023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211692023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211702023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211712023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211722023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211732023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211742023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211752023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211762023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211772023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211782023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211792023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211802023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211812023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211822023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211832023-04-10 09:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211842023-04-10 09:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211852023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211862023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211872023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211882023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211892023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211902023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211912023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211922023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211932023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211942023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211952023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211962023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211972023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
211982023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
211992023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212002023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212012023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212022023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212032023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212042023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212052023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212062023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212072023-04-10 09:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212082023-04-10 09:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212092023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212102023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212112023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212122023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212132023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212142023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212152023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212162023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212172023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212182023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212192023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212202023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212212023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212222023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212232023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212242023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212252023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212262023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212272023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212282023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212292023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212302023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212312023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212322023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212332023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212342023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212352023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212362023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212372023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212382023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212392023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212402023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212412023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212422023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212432023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212442023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212452023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212462023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212472023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212482023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212492023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212502023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212512023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212522023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212532023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212542023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212552023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212562023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212572023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212582023-04-10 09:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
212592023-04-10 09:45:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
212602023-04-10 09:45:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
212612023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212622023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212632023-04-10 09:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212642023-04-10 09:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212652023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212662023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212672023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212682023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212692023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212702023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212712023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212722023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212732023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212742023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212752023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212762023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212772023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212782023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212792023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212802023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212812023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212822023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212832023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212842023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212852023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
212862023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
212872023-04-10 09:44:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x431F441||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
212882023-04-10 09:44:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x431FED6||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
212892023-04-10 09:44:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x431F495||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
212902023-04-10 09:44:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x4320099||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
212912023-04-10 09:44:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x431FED6||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
212922023-04-10 09:44:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x4320099| Linked Logon ID: 0x431FED6| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
212932023-04-10 09:44:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x431FED6| Linked Logon ID: 0x4320099| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
212942023-04-10 09:44:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
212952023-04-10 09:44:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
212962023-04-10 09:44:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
212972023-04-10 09:44:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
212982023-04-10 09:44:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x431F441||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
212992023-04-10 09:44:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x431F495| Linked Logon ID: 0x431F441| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
213002023-04-10 09:44:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x431F441| Linked Logon ID: 0x431F495| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
213012023-04-10 09:44:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
213022023-04-10 09:44:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
213032023-04-10 09:44:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
213042023-04-10 09:44:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
213052023-04-10 09:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213062023-04-10 09:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213072023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213082023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213092023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213102023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213112023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213122023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213132023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213142023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213152023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213162023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213172023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213182023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213192023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213202023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213212023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213222023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213232023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213242023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213252023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213262023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213272023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213282023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213292023-04-10 09:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213302023-04-10 09:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213312023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213322023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213332023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213342023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213352023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213362023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213372023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213382023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213392023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213402023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213412023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213422023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213432023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213442023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213452023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213462023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213472023-04-10 09:42:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
213482023-04-10 09:42:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
213492023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213502023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213512023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213522023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213532023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213542023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213552023-04-10 09:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213562023-04-10 09:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213572023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213582023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213592023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213602023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213612023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213622023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213632023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213642023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213652023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213662023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213672023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213682023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213692023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213702023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213712023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213722023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213732023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213742023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213752023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213762023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213772023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213782023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213792023-04-10 09:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213802023-04-10 09:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213812023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213822023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213832023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213842023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213852023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213862023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213872023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213882023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213892023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213902023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213912023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213922023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213932023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213942023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213952023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213962023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213972023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
213982023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
213992023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214002023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214012023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214022023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214032023-04-10 09:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214042023-04-10 09:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214052023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214062023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214072023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214082023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214092023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214102023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214112023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214122023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214132023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214142023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214152023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214162023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214172023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214182023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214192023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214202023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214212023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214222023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214232023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214242023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214252023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214262023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214272023-04-10 09:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214282023-04-10 09:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214292023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214302023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214312023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214322023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214332023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214342023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214352023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214362023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214372023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214382023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214392023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214402023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214412023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214422023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214432023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214442023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214452023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214462023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214472023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214482023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214492023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214502023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214512023-04-10 09:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214522023-04-10 09:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214532023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214542023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214552023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214562023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214572023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214582023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214592023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214602023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214612023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214622023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214632023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214642023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214652023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214662023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214672023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214682023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214692023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214702023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214712023-04-10 09:37:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
214722023-04-10 09:37:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
214732023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214742023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214752023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214762023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214772023-04-10 09:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214782023-04-10 09:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214792023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214802023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214812023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214822023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214832023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214842023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214852023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214862023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214872023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214882023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214892023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214902023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214912023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214922023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214932023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214942023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214952023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214962023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214972023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
214982023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
214992023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215002023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215012023-04-10 09:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215022023-04-10 09:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215032023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215042023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215052023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215062023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215072023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215082023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215092023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215102023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215112023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215122023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215132023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215142023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215152023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215162023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215172023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215182023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215192023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215202023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215212023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215222023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215232023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215242023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215252023-04-10 09:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215262023-04-10 09:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215272023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215282023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215292023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215302023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215312023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215322023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215332023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215342023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215352023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215362023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215372023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215382023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215392023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215402023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215412023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215422023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215432023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215442023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215452023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215462023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215472023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215482023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215492023-04-10 09:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215502023-04-10 09:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215512023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215522023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215532023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215542023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215552023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215562023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215572023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215582023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215592023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215602023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215612023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215622023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215632023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215642023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215652023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215662023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215672023-04-10 09:33:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
215682023-04-10 09:33:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
215692023-04-10 09:33:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
215702023-04-10 09:33:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
215712023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215722023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215732023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215742023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215752023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215762023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215772023-04-10 09:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215782023-04-10 09:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215792023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215802023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215812023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215822023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215832023-04-10 09:32:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0xcd4| Process Name: C:\Windows\System32\LogonUI.exe
215842023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215852023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215862023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215872023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215882023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215892023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215902023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215912023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215922023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215932023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215942023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215952023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215962023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215972023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
215982023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
215992023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216002023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216012023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216022023-04-10 09:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216032023-04-10 09:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216042023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216052023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216062023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216072023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216082023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216092023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216102023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216112023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216122023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216132023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216142023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216152023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216162023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216172023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216182023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216192023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216202023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216212023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216222023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216232023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216242023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216252023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216262023-04-10 09:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216272023-04-10 09:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216282023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216292023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216302023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216312023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216322023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216332023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216342023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216352023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216362023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216372023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216382023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216392023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216402023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216412023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216422023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216432023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216442023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216452023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216462023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216472023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216482023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216492023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216502023-04-10 09:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216512023-04-10 09:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216522023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216532023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216542023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216552023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216562023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216572023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216582023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216592023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216602023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216612023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216622023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216632023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216642023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216652023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216662023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216672023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216682023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216692023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216702023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216712023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216722023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216732023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216742023-04-10 09:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216752023-04-10 09:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216762023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216772023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216782023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216792023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216802023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216812023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216822023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216832023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216842023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216852023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216862023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216872023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216882023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216892023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216902023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216912023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216922023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216932023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216942023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216952023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216962023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216972023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
216982023-04-10 09:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
216992023-04-10 09:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217002023-04-10 09:27:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
217012023-04-10 09:27:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
217022023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217032023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217042023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217052023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217062023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217072023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217082023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217092023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217102023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217112023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217122023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217132023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217142023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217152023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217162023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217172023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217182023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217192023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217202023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217212023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217222023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217232023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217242023-04-10 09:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217252023-04-10 09:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217262023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217272023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217282023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217292023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217302023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217312023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217322023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217332023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217342023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217352023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217362023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217372023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217382023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217392023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217402023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217412023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217422023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217432023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217442023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217452023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217462023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217472023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217482023-04-10 09:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217492023-04-10 09:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217502023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217512023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217522023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217532023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217542023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217552023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217562023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217572023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217582023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217592023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217602023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217612023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217622023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217632023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217642023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217652023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217662023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217672023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217682023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217692023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217702023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217712023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217722023-04-10 09:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217732023-04-10 09:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217742023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217752023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217762023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217772023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217782023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217792023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217802023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217812023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217822023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217832023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217842023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217852023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217862023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217872023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217882023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217892023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217902023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217912023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217922023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217932023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217942023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217952023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217962023-04-10 09:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217972023-04-10 09:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
217982023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
217992023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218002023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218012023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218022023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218032023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218042023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218052023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218062023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218072023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218082023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218092023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218102023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218112023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218122023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218132023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218142023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218152023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218162023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218172023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218182023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218192023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218202023-04-10 09:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218212023-04-10 09:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218222023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218232023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218242023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218252023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218262023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218272023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218282023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218292023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218302023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218312023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218322023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218332023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218342023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218352023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218362023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218372023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218382023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218392023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218402023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218412023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218422023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218432023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218442023-04-10 09:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218452023-04-10 09:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218462023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218472023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218482023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218492023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218502023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218512023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218522023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218532023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218542023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218552023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218562023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218572023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218582023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218592023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218602023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218612023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218622023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218632023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218642023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218652023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218662023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218672023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218682023-04-10 09:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218692023-04-10 09:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218702023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218712023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218722023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218732023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218742023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218752023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218762023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218772023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218782023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218792023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218802023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218812023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218822023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218832023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218842023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218852023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218862023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218872023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218882023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218892023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218902023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218912023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218922023-04-10 09:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218932023-04-10 09:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218942023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218952023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218962023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218972023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
218982023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
218992023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219002023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219012023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219022023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219032023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219042023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219052023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219062023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219072023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219082023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219092023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219102023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219112023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219122023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219132023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219142023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219152023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219162023-04-10 09:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219172023-04-10 09:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219182023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219192023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219202023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219212023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219222023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219232023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219242023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219252023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219262023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219272023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219282023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219292023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219302023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219312023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219322023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219332023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219342023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219352023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219362023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219372023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219382023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219392023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219402023-04-10 09:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219412023-04-10 09:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219422023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219432023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219442023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219452023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219462023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219472023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219482023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219492023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219502023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219512023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219522023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219532023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219542023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219552023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219562023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219572023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219582023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219592023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219602023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219612023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219622023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219632023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219642023-04-10 09:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219652023-04-10 09:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219662023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219672023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219682023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219692023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219702023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219712023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219722023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219732023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219742023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219752023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219762023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219772023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219782023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219792023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219802023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219812023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219822023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219832023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219842023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219852023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219862023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219872023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219882023-04-10 09:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219892023-04-10 09:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219902023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219912023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219922023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219932023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219942023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219952023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219962023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219972023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
219982023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
219992023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220002023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220012023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220022023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220032023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220042023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220052023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220062023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220072023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220082023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220092023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220102023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220112023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220122023-04-10 09:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220132023-04-10 09:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220142023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220152023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220162023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220172023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220182023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220192023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220202023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220212023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220222023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220232023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220242023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220252023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220262023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220272023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220282023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220292023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220302023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220312023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220322023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220332023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220342023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220352023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220362023-04-10 09:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220372023-04-10 09:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220382023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220392023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220402023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220412023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220422023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220432023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220442023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220452023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220462023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220472023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220482023-04-10 09:13:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
220492023-04-10 09:13:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
220502023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220512023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220522023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220532023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220542023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220552023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220562023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220572023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220582023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220592023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220602023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220612023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220622023-04-10 09:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220632023-04-10 09:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220642023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220652023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220662023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220672023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220682023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220692023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220702023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220712023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220722023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220732023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220742023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220752023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220762023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220772023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220782023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220792023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220802023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220812023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220822023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220832023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220842023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220852023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220862023-04-10 09:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220872023-04-10 09:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220882023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220892023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220902023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220912023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220922023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220932023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220942023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220952023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220962023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220972023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
220982023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
220992023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221002023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221012023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221022023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221032023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221042023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221052023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221062023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221072023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221082023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221092023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221102023-04-10 09:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221112023-04-10 09:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221122023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221132023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221142023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221152023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221162023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221172023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221182023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221192023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221202023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221212023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221222023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221232023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221242023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221252023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221262023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221272023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221282023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221292023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221302023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221312023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221322023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221332023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221342023-04-10 09:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221352023-04-10 09:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221362023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221372023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221382023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221392023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221402023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221412023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221422023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221432023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221442023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221452023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221462023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221472023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221482023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221492023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221502023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221512023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221522023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221532023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221542023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221552023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221562023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221572023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221582023-04-10 09:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221592023-04-10 09:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221602023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221612023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221622023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221632023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221642023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221652023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221662023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221672023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221682023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221692023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221702023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221712023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221722023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221732023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221742023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221752023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221762023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221772023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221782023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221792023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221802023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221812023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221822023-04-10 09:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221832023-04-10 09:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221842023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221852023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221862023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221872023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221882023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221892023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221902023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221912023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221922023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221932023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221942023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221952023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221962023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221972023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
221982023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
221992023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222002023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222012023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222022023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222032023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222042023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222052023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222062023-04-10 09:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222072023-04-10 09:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222082023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222092023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222102023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222112023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222122023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222132023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222142023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222152023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222162023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222172023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222182023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222192023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222202023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222212023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222222023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222232023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222242023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222252023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222262023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222272023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222282023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222292023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222302023-04-10 09:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222312023-04-10 09:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222322023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222332023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222342023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222352023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222362023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222372023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222382023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222392023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222402023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222412023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222422023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222432023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222442023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222452023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222462023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222472023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222482023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222492023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222502023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222512023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222522023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222532023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222542023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222552023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222562023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222572023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222582023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222592023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222602023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222612023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222622023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222632023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222642023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222652023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222662023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222672023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222682023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222692023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222702023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222712023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222722023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222732023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222742023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222752023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222762023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222772023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222782023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222792023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222802023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222812023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222822023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222832023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222842023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222852023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222862023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222872023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222882023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222892023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222902023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222912023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222922023-04-10 09:05:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
222932023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222942023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222952023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222962023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222972023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
222982023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
222992023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223002023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223012023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223022023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223032023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223042023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223052023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223062023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223072023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223082023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223092023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223102023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223112023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223122023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223132023-04-10 09:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223142023-04-10 09:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223152023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223162023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223172023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223182023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223192023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223202023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223212023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223222023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223232023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223242023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223252023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223262023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223272023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223282023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223292023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223302023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223312023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223322023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223332023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223342023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223352023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223362023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223372023-04-10 09:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
223382023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223392023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223402023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223412023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223422023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223432023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223442023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223452023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223462023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223472023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223482023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223492023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223502023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223512023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223522023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223532023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223542023-04-10 09:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223552023-04-10 09:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223562023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223572023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223582023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223592023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223602023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223612023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223622023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223632023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223642023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223652023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223662023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223672023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223682023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223692023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223702023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223712023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223722023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223732023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223742023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223752023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223762023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223772023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223782023-04-10 09:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223792023-04-10 09:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223802023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223812023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223822023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223832023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223842023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223852023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223862023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223872023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223882023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223892023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223902023-04-10 09:02:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
223912023-04-10 09:02:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
223922023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223932023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223942023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223952023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223962023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223972023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
223982023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
223992023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224002023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224012023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224022023-04-10 09:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224032023-04-10 09:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224042023-04-10 09:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224052023-04-10 09:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224062023-04-10 09:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224072023-04-10 09:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224082023-04-10 09:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224092023-04-10 09:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224102023-04-10 09:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224112023-04-10 09:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: NETWORK SERVICE| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224122023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224132023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224142023-04-10 09:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224152023-04-10 09:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224162023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224172023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224182023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224192023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224202023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224212023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224222023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224232023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224242023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224252023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224262023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224272023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224282023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224292023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224302023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224312023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224322023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224332023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224342023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224352023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224362023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224372023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224382023-04-10 09:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224392023-04-10 09:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224402023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224412023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224422023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224432023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224442023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224452023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224462023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224472023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224482023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224492023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224502023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224512023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224522023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224532023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224542023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224552023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224562023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224572023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224582023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224592023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224602023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224612023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224622023-04-10 09:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224632023-04-10 09:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224642023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224652023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224662023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224672023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224682023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224692023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224702023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224712023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224722023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224732023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224742023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224752023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224762023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224772023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224782023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224792023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224802023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224812023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224822023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224832023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224842023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224852023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224862023-04-10 08:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224872023-04-10 08:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224882023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224892023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224902023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224912023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224922023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224932023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224942023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
224952023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
224962023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224972023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224982023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
224992023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225002023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225012023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225022023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225032023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225042023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225052023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225062023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225072023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225082023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225092023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225102023-04-10 08:58:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225112023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225122023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225132023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225142023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225152023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225162023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225172023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225182023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225192023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225202023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225212023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225222023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225232023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225242023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225252023-04-10 08:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225262023-04-10 08:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225272023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225282023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225292023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225302023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225312023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225322023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225332023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225342023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225352023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225362023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225372023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225382023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225392023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225402023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225412023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225422023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
225432023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
225442023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225452023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225462023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225472023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225482023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225492023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225502023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225512023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225522023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225532023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225542023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225552023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225562023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225572023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225582023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225592023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225602023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225612023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225622023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225632023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225642023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225652023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225662023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225672023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225682023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225692023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225702023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225712023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225722023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225732023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225742023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225752023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225762023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225772023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225782023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225792023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225802023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225812023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225822023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225832023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225842023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225852023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225862023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225872023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225882023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225892023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225902023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225912023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225922023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225932023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225942023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225952023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225962023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225972023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225982023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
225992023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226002023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226012023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226022023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226032023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226042023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226052023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226062023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226072023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226082023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226092023-04-10 08:57:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226102023-04-10 08:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226112023-04-10 08:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226122023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226132023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226142023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226152023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226162023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226172023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226182023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226192023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226202023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226212023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226222023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226232023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226242023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226252023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226262023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226272023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226282023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226292023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226302023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226312023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226322023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226332023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226342023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226352023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226362023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226372023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226382023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226392023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226402023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226412023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226422023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226432023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226442023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226452023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226462023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226472023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226482023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226492023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226502023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226512023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226522023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226532023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226542023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226552023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226562023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226572023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226582023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226592023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226602023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226612023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226622023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226632023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226642023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226652023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226662023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226672023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226682023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226692023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226702023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226712023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226722023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226732023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226742023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226752023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226762023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226772023-04-10 08:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
226782023-04-10 08:56:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
226792023-04-10 08:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
226802023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226812023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226822023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226832023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226842023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226852023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226862023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226872023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226882023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226892023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226902023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226912023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226922023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226932023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226942023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226952023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226962023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226972023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
226982023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
226992023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227002023-04-10 08:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227012023-04-10 08:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227022023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227032023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227042023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227052023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227062023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227072023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227082023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227092023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227102023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227112023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227122023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227132023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227142023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227152023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227162023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227172023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227182023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227192023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227202023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227212023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227222023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227232023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227242023-04-10 08:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227252023-04-10 08:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227262023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227272023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227282023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227292023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227302023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227312023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227322023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227332023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227342023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227352023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227362023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227372023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227382023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227392023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227402023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227412023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227422023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227432023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227442023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227452023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227462023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227472023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227482023-04-10 08:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227492023-04-10 08:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227502023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227512023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227522023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227532023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227542023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227552023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227562023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227572023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227582023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227592023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227602023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227612023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227622023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227632023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227642023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227652023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227662023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227672023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227682023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227692023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227702023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227712023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227722023-04-10 08:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227732023-04-10 08:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227742023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227752023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227762023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227772023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227782023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227792023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227802023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227812023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227822023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227832023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
227842023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
227852023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227862023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227872023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227882023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227892023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227902023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227912023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227922023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227932023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227942023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227952023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227962023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227972023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227982023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
227992023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228002023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228012023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228022023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228032023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228042023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228052023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228062023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228072023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228082023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228092023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228102023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228112023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228122023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228132023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228142023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228152023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228162023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228172023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228182023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228192023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228202023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228212023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228222023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228232023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228242023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228252023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228262023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228272023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228282023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228292023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228302023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228312023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228322023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228332023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228342023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228352023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228362023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228372023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228382023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228392023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228402023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228412023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228422023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228432023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228442023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228452023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228462023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228472023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228482023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228492023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228502023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228512023-04-10 08:52:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
228522023-04-10 08:52:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
228532023-04-10 08:52:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
228542023-04-10 08:52:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
228552023-04-10 08:52:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
228562023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228572023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228582023-04-10 08:52:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
228592023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228602023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228612023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228622023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228632023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228642023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228652023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228662023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228672023-04-10 08:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228682023-04-10 08:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228692023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228702023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228712023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228722023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228732023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228742023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228752023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228762023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228772023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228782023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228792023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228802023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228812023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228822023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228832023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228842023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228852023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228862023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228872023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228882023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228892023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228902023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228912023-04-10 08:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228922023-04-10 08:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228932023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228942023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228952023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228962023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228972023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
228982023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
228992023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229002023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229012023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229022023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229032023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229042023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229052023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229062023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229072023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229082023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229092023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229102023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229112023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229122023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229132023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229142023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229152023-04-10 08:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229162023-04-10 08:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229172023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229182023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229192023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229202023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229212023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229222023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229232023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229242023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229252023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229262023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229272023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229282023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229292023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229302023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229312023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229322023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229332023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229342023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229352023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229362023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229372023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229382023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229392023-04-10 08:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229402023-04-10 08:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229412023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229422023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229432023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229442023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229452023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229462023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229472023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229482023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229492023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229502023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229512023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229522023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229532023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229542023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229552023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229562023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229572023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229582023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229592023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229602023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229612023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229622023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229632023-04-10 08:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229642023-04-10 08:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229652023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229662023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229672023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229682023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229692023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229702023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229712023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229722023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229732023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229742023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229752023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229762023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229772023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229782023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229792023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229802023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229812023-04-10 08:47:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
229822023-04-10 08:47:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
229832023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229842023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229852023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229862023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229872023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229882023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229892023-04-10 08:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229902023-04-10 08:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229912023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229922023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229932023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229942023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229952023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229962023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229972023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
229982023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
229992023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230002023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230012023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230022023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230032023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230042023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230052023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230062023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230072023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230082023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230092023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230102023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230112023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230122023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230132023-04-10 08:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230142023-04-10 08:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230152023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230162023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230172023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230182023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230192023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230202023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230212023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230222023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230232023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230242023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230252023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230262023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230272023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230282023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230292023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230302023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230312023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
230322023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
230332023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230342023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230352023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230362023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230372023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230382023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230392023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230402023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230412023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230422023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230432023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230442023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230452023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230462023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230472023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230482023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230492023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230502023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230512023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230522023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230532023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230542023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230552023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230562023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230572023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230582023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230592023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230602023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230612023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230622023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230632023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230642023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230652023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230662023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230672023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230682023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230692023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230702023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230712023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230722023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230732023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230742023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230752023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230762023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230772023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230782023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230792023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230802023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230812023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230822023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230832023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230842023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230852023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230862023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230872023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230882023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230892023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230902023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230912023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230922023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230932023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230942023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230952023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230962023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230972023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230982023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
230992023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231002023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231012023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231022023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231032023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231042023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231052023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231062023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231072023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231082023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231092023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231102023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231112023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231122023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231132023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231142023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231152023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231162023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231172023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231182023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231192023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231202023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231212023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231222023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231232023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231242023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231252023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231262023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231272023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231282023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231292023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231302023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231312023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231322023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231332023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231342023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231352023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231362023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231372023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231382023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231392023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231402023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231412023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231422023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231432023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231442023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231452023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231462023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231472023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231482023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231492023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231502023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231512023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231522023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231532023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231542023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231552023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231562023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231572023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231582023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
231592023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
231602023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231612023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231622023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231632023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231642023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231652023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231662023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231672023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231682023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231692023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231702023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231712023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231722023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231732023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231742023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231752023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231762023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231772023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231782023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231792023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231802023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231812023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231822023-04-10 08:45:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 23388| Process Creation Time: ‎2023‎-‎10‎-‎04T12:45:06.111585500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: FOCIPOPKEY_S-1-5-21-1318052574-1909131979-1541577531-1001_sw| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
231832023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: FOCIPOPKEY_S-1-5-21-1318052574-1909131979-1541577531-1001_sw| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
231842023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 23388| Process Creation Time: ‎2023‎-‎10‎-‎04T12:45:06.111585500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: FOCIPOPKEY_S-1-5-21-1318052574-1909131979-1541577531-1001_sw| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\a26cab42e05cd328c85d71a4391ccfbc_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
231852023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231862023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231872023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231882023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231892023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231902023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231912023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231922023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231932023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231942023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231952023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231962023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231972023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231982023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
231992023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232002023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232012023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232022023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232032023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232042023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232052023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232062023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232072023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232082023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232092023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232102023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232112023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232122023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232132023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232142023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232152023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232162023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232172023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232182023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232192023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232202023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232212023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232222023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232232023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232242023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232252023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232262023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232272023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232282023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232292023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232302023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232312023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232322023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232332023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232342023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232352023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232362023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232372023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232382023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232392023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232402023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232412023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232422023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232432023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232442023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232452023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232462023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232472023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232482023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232492023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232502023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232512023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232522023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232532023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232542023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232552023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232562023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232572023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232582023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232592023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232602023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232612023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232622023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232632023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232642023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232652023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232662023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232672023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232682023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232692023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232702023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232712023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232722023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232732023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232742023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232752023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232762023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232772023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232782023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232792023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232802023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232812023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232822023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232832023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232842023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232852023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232862023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232872023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232882023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232892023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232902023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232912023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232922023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232932023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232942023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232952023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232962023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232972023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232982023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
232992023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233002023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233012023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233022023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233032023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233042023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233052023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233062023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233072023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233082023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233092023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233102023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233112023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233122023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233132023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233142023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233152023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233162023-04-10 08:45:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233172023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
233182023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
233192023-04-10 08:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
233202023-04-10 08:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
233212023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233222023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233232023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233242023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233252023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233262023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233272023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233282023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233292023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233302023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233312023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233322023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233332023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233342023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233352023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233362023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233372023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233382023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233392023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233402023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233412023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233422023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233432023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233442023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233452023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233462023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233472023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233482023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233492023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233502023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233512023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233522023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233532023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233542023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233552023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233562023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233572023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233582023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233592023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233602023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233612023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233622023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233632023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233642023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233652023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233662023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233672023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233682023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233692023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233702023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233712023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233722023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233732023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233742023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233752023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233762023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233772023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233782023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233792023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233802023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233812023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233822023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233832023-04-10 08:44:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
233842023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
233852023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
233862023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
233872023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
233882023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
233892023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
233902023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
233912023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
233922023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
233932023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
233942023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
233952023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
233962023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
233972023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
233982023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
233992023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234002023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234012023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234022023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234032023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234042023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234052023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234062023-04-10 08:44:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
234072023-04-10 08:44:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
234082023-04-10 08:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234092023-04-10 08:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234102023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234112023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234122023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234132023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234142023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234152023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234162023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234172023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234182023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234192023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234202023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234212023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234222023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234232023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234242023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234252023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234262023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234272023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234282023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234292023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234302023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234312023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234322023-04-10 08:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234332023-04-10 08:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234342023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234352023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234362023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234372023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234382023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234392023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234402023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234412023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234422023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234432023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234442023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234452023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234462023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234472023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234482023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234492023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234502023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234512023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234522023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234532023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234542023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234552023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234562023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234572023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234582023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234592023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234602023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234612023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234622023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234632023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234642023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234652023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234662023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234672023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234682023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234692023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234702023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234712023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234722023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234732023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234742023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234752023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234762023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234772023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234782023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234792023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234802023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234812023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234822023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
234832023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
234842023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234852023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234862023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234872023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234882023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234892023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234902023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234912023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234922023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234932023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234942023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234952023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234962023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234972023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234982023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
234992023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235002023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235012023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235022023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235032023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235042023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235052023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
235062023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
235072023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
235082023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
235092023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
235102023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
235112023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
235122023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
235132023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
235142023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
235152023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
235162023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
235172023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
235182023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
235192023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
235202023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
235212023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
235222023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235232023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235242023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235252023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235262023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235272023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235282023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235292023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235302023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235312023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235322023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235332023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235342023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235352023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235362023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235372023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235382023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235392023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235402023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235412023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235422023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235432023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235442023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235452023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235462023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235472023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235482023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235492023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235502023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235512023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235522023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235532023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235542023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235552023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235562023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235572023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235582023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235592023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235602023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235612023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235622023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235632023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235642023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235652023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235662023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235672023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235682023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235692023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235702023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235712023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235722023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235732023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235742023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235752023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235762023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235772023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235782023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235792023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235802023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235812023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235822023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235832023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235842023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235852023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235862023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235872023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235882023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235892023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235902023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235912023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235922023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235932023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235942023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235952023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235962023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235972023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235982023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
235992023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236002023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236012023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236022023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236032023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236042023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236052023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236062023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236072023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236082023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236092023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236102023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236112023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236122023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236132023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236142023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236152023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236162023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236172023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236182023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236192023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236202023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236212023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236222023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236232023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236242023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236252023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236262023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236272023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236282023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236292023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236302023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236312023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236322023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236332023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236342023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236352023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236362023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236372023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236382023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236392023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236402023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236412023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236422023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236432023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236442023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236452023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236462023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236472023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236482023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236492023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236502023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236512023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236522023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236532023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236542023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236552023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236562023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236572023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236582023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236592023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236602023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236612023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236622023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236632023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236642023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236652023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236662023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236672023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236682023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236692023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236702023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236712023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236722023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236732023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236742023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236752023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236762023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236772023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236782023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236792023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236802023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236812023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236822023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236832023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236842023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236852023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236862023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236872023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236882023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236892023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236902023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236912023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236922023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236932023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236942023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236952023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236962023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236972023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236982023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
236992023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237002023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237012023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237022023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237032023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237042023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237052023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237062023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237072023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237082023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237092023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237102023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237112023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237122023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237132023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237142023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237152023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237162023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237172023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237182023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
237192023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237202023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
237212023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237222023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237232023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237242023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237252023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237262023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237272023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237282023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237292023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237302023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237312023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237322023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237332023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237342023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237352023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237362023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237372023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237382023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237392023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237402023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237412023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237422023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237432023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237442023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237452023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237462023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237472023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237482023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237492023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237502023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237512023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237522023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237532023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237542023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237552023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237562023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237572023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237582023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237592023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237602023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237612023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237622023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237632023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
237642023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237652023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237662023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237672023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237682023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237692023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237702023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237712023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237722023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237732023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237742023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237752023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237762023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237772023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237782023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237792023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237802023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237812023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237822023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237832023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237842023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237852023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237862023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237872023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237882023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237892023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237902023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237912023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237922023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237932023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237942023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237952023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237962023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237972023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237982023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
237992023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238002023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238012023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238022023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238032023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238042023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238052023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238062023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238072023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238082023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238092023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238102023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238112023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238122023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238132023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238142023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238152023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238162023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238172023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238182023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238192023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238202023-04-10 08:42:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
238212023-04-10 08:42:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
238222023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238232023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238242023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238252023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238262023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238272023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238282023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238292023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238302023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238312023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238322023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238332023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238342023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238352023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238362023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238372023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238382023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238392023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238402023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238412023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238422023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238432023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238442023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238452023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238462023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238472023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238482023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238492023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238502023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238512023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238522023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238532023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238542023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238552023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238562023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238572023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238582023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238592023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238602023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238612023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238622023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238632023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238642023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238652023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238662023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238672023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238682023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238692023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238702023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238712023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238722023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238732023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238742023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238752023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238762023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238772023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238782023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238792023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238802023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238812023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238822023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238832023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238842023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238852023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238862023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238872023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238882023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238892023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
238902023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
238912023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238922023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238932023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238942023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238952023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238962023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238972023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238982023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
238992023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239002023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239012023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239022023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239032023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239042023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239052023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239062023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239072023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239082023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239092023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239102023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239112023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239122023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239132023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239142023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239152023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239162023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
239172023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
239182023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239192023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239202023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239212023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239222023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239232023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239242023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239252023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239262023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239272023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239282023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239292023-04-10 08:42:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x3AD5399||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
239302023-04-10 08:42:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x3AD3D19||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
239312023-04-10 08:42:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x3AD545F||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
239322023-04-10 08:42:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x3AD3D91||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
239332023-04-10 08:42:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x3AD5399||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
239342023-04-10 08:42:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x3AD545F| Linked Logon ID: 0x3AD5399| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
239352023-04-10 08:42:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x3AD5399| Linked Logon ID: 0x3AD545F| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
239362023-04-10 08:42:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
239372023-04-10 08:42:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
239382023-04-10 08:42:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
239392023-04-10 08:42:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
239402023-04-10 08:42:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x3AD3D19||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
239412023-04-10 08:42:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x3AD3D91| Linked Logon ID: 0x3AD3D19| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
239422023-04-10 08:42:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x3AD3D19| Linked Logon ID: 0x3AD3D91| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
239432023-04-10 08:42:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
239442023-04-10 08:42:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
239452023-04-10 08:42:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
239462023-04-10 08:42:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
239472023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239482023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239492023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239502023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239512023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239522023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239532023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239542023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239552023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239562023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239572023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239582023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239592023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239602023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239612023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239622023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239632023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239642023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239652023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239662023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239672023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239682023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239692023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239702023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239712023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239722023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239732023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239742023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239752023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239762023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239772023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239782023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239792023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239802023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239812023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239822023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239832023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239842023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239852023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239862023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239872023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239882023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239892023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239902023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239912023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239922023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239932023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239942023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239952023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239962023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239972023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239982023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
239992023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240002023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240012023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240022023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240032023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240042023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240052023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240062023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240072023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240082023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240092023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240102023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240112023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240122023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240132023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240142023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240152023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240162023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240172023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240182023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240192023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240202023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240212023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240222023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240232023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240242023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240252023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240262023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240272023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240282023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240292023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240302023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240312023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240322023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240332023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240342023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240352023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240362023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240372023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240382023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240392023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240402023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240412023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240422023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240432023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240442023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240452023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240462023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240472023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240482023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240492023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240502023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240512023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240522023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240532023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240542023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
240552023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
240562023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240572023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240582023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240592023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240602023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240612023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240622023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240632023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240642023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240652023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240662023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240672023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240682023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240692023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240702023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240712023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240722023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240732023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240742023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240752023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240762023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240772023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240782023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240792023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240802023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240812023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240822023-04-10 08:42:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
240832023-04-10 08:42:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
240842023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240852023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240862023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240872023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240882023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240892023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240902023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240912023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240922023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240932023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240942023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240952023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240962023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240972023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240982023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
240992023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241002023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241012023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241022023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241032023-04-10 08:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
241042023-04-10 08:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
241052023-04-10 08:42:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x3dfc| Process Name: C:\Windows\System32\LogonUI.exe
241062023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241072023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241082023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241092023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241102023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241112023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241122023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241132023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241142023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241152023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241162023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241172023-04-10 08:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241182023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241192023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241202023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241212023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241222023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241232023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241242023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241252023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241262023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241272023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241282023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241292023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241302023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241312023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241322023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241332023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241342023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
241352023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241362023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241372023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241382023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241392023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241402023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241412023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241422023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241432023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241442023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241452023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241462023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241472023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241482023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241492023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241502023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241512023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241522023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241532023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241542023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241552023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241562023-04-10 04:56:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
241572023-04-10 04:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
241582023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
241592023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
241602023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
241612023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
241622023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
241632023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
241642023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
241652023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
241662023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
241672023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
241682023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
241692023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
241702023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
241712023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
241722023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
241732023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
241742023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
241752023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
241762023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241772023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241782023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241792023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241802023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241812023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241822023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241832023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241842023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241852023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241862023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241872023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241882023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241892023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241902023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241912023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241922023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241932023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241942023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241952023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241962023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241972023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241982023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
241992023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242002023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242012023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242022023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242032023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242042023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242052023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242062023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242072023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242082023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242092023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242102023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242112023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242122023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242132023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242142023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242152023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242162023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242172023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242182023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242192023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242202023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242212023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242222023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242232023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242242023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242252023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242262023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
242272023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
242282023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
242292023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
242302023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
242312023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
242322023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242332023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242342023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242352023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242362023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242372023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242382023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242392023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242402023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242412023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242422023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242432023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242442023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242452023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242462023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242472023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242482023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242492023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242502023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242512023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242522023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242532023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242542023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242552023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242562023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242572023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242582023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242592023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242602023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242612023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242622023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242632023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242642023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242652023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242662023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242672023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242682023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242692023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242702023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242712023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242722023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242732023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242742023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242752023-04-10 04:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242762023-04-10 04:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
242772023-04-10 04:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
242782023-04-10 04:56:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
242792023-04-10 04:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
242802023-04-10 04:56:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
242812023-04-10 04:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
242822023-04-10 00:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
242832023-04-10 00:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
242842023-04-10 00:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
242852023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242862023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242872023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242882023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242892023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242902023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242912023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242922023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242932023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242942023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242952023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242962023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242972023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242982023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
242992023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243002023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243012023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243022023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243032023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243042023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243052023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243062023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243072023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243082023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243092023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243102023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243112023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243122023-04-10 00:56:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
243132023-04-10 00:56:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
243142023-04-10 00:56:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
243152023-04-10 00:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243162023-04-10 00:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243172023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243182023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243192023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243202023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243212023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243222023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243232023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243242023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243252023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243262023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243272023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243282023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243292023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243302023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243312023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243322023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243332023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243342023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243352023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243362023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243372023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243382023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243392023-04-10 00:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243402023-04-10 00:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243412023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243422023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243432023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243442023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243452023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243462023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243472023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243482023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243492023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243502023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243512023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243522023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243532023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243542023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243552023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243562023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243572023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243582023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243592023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243602023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243612023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243622023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243632023-04-10 00:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243642023-04-10 00:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243652023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243662023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243672023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243682023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243692023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243702023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243712023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243722023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243732023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243742023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243752023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243762023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243772023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243782023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243792023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243802023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243812023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243822023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243832023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243842023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243852023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243862023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243872023-04-10 00:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243882023-04-10 00:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243892023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243902023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243912023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243922023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243932023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243942023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243952023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243962023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243972023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
243982023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
243992023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244002023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244012023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244022023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244032023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244042023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244052023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244062023-04-10 00:52:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
244072023-04-10 00:52:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
244082023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244092023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244102023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244112023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244122023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244132023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244142023-04-10 00:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244152023-04-10 00:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244162023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244172023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244182023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244192023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244202023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244212023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244222023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244232023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244242023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244252023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244262023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244272023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244282023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244292023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244302023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244312023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244322023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244332023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244342023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244352023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244362023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244372023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244382023-04-10 00:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244392023-04-10 00:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244402023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244412023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244422023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244432023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244442023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244452023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244462023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244472023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244482023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244492023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244502023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244512023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244522023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244532023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244542023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244552023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244562023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244572023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244582023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244592023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244602023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244612023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244622023-04-10 00:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244632023-04-10 00:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244642023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244652023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244662023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244672023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244682023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244692023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244702023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244712023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244722023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244732023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244742023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244752023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244762023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244772023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244782023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244792023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244802023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244812023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244822023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244832023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244842023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244852023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244862023-04-10 00:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244872023-04-10 00:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244882023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244892023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244902023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244912023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244922023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244932023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244942023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244952023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244962023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244972023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
244982023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
244992023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245002023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245012023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245022023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245032023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245042023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245052023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245062023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245072023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245082023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245092023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245102023-04-10 00:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245112023-04-10 00:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245122023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245132023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245142023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245152023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245162023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245172023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245182023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245192023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245202023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245212023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245222023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245232023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245242023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245252023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245262023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245272023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245282023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245292023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245302023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245312023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245322023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245332023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245342023-04-10 00:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245352023-04-10 00:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245362023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245372023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245382023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245392023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245402023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245412023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245422023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245432023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245442023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245452023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245462023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245472023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245482023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245492023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245502023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245512023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245522023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245532023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245542023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245552023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245562023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245572023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245582023-04-10 00:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245592023-04-10 00:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245602023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245612023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245622023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245632023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245642023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245652023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245662023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245672023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245682023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245692023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245702023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245712023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245722023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245732023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245742023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245752023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245762023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245772023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245782023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245792023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245802023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245812023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245822023-04-10 00:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245832023-04-10 00:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245842023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245852023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245862023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245872023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245882023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245892023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245902023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245912023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245922023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245932023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245942023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245952023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245962023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245972023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
245982023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
245992023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246002023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246012023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246022023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246032023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246042023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246052023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246062023-04-10 00:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246072023-04-10 00:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246082023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246092023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246102023-04-10 00:43:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
246112023-04-10 00:43:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
246122023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246132023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246142023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246152023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246162023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246172023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246182023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246192023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246202023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246212023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246222023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246232023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246242023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246252023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246262023-04-10 00:43:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
246272023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246282023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246292023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246302023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246312023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246322023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246332023-04-10 00:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246342023-04-10 00:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246352023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246362023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246372023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246382023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246392023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246402023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246412023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246422023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246432023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246442023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246452023-04-10 00:42:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
246462023-04-10 00:42:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
246472023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246482023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246492023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246502023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246512023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246522023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246532023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246542023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246552023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246562023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246572023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246582023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246592023-04-10 00:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246602023-04-10 00:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246612023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246622023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246632023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246642023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246652023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246662023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246672023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246682023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246692023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246702023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246712023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246722023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246732023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246742023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246752023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246762023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246772023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246782023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246792023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246802023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246812023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246822023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246832023-04-10 00:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246842023-04-10 00:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246852023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246862023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246872023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246882023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246892023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246902023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246912023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246922023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246932023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246942023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246952023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246962023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246972023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
246982023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
246992023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247002023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247012023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247022023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247032023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247042023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247052023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247062023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247072023-04-10 00:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247082023-04-10 00:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247092023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247102023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247112023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247122023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247132023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247142023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247152023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247162023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247172023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247182023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247192023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247202023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247212023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247222023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247232023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247242023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247252023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247262023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247272023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247282023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247292023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247302023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247312023-04-10 00:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247322023-04-10 00:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247332023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247342023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247352023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247362023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247372023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247382023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247392023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247402023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247412023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247422023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247432023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247442023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247452023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247462023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247472023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247482023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247492023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247502023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247512023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247522023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247532023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247542023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247552023-04-10 00:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247562023-04-10 00:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247572023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247582023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247592023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247602023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247612023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247622023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247632023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247642023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247652023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247662023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247672023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247682023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247692023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247702023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247712023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247722023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247732023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247742023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247752023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247762023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247772023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247782023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247792023-04-10 00:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247802023-04-10 00:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247812023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247822023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247832023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247842023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247852023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247862023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247872023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247882023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247892023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247902023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247912023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247922023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247932023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247942023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247952023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247962023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247972023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
247982023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
247992023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248002023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248012023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248022023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248032023-04-10 00:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248042023-04-10 00:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248052023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248062023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248072023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248082023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248092023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248102023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248112023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248122023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248132023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248142023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248152023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248162023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248172023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248182023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248192023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248202023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248212023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248222023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248232023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248242023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248252023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248262023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248272023-04-10 00:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248282023-04-10 00:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248292023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248302023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248312023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248322023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248332023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248342023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248352023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248362023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248372023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248382023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248392023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248402023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248412023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248422023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248432023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248442023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248452023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248462023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248472023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248482023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248492023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248502023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248512023-04-10 00:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248522023-04-10 00:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248532023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248542023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248552023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248562023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248572023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248582023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248592023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248602023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248612023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248622023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248632023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248642023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248652023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248662023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248672023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248682023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248692023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248702023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248712023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248722023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248732023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248742023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248752023-04-10 00:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248762023-04-10 00:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248772023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248782023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248792023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248802023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248812023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248822023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248832023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248842023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248852023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248862023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248872023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248882023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248892023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248902023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248912023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248922023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248932023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248942023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248952023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248962023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248972023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
248982023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
248992023-04-10 00:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249002023-04-10 00:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249012023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249022023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249032023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249042023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249052023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249062023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249072023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249082023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249092023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249102023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249112023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249122023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249132023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249142023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249152023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249162023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249172023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249182023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249192023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249202023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249212023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249222023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249232023-04-10 00:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249242023-04-10 00:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249252023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249262023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249272023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249282023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249292023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249302023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249312023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249322023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249332023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249342023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249352023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249362023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249372023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249382023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249392023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249402023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249412023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249422023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249432023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249442023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249452023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249462023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249472023-04-10 00:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249482023-04-10 00:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249492023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249502023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249512023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249522023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249532023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249542023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249552023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249562023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249572023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249582023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249592023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249602023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249612023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249622023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249632023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249642023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249652023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249662023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249672023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249682023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249692023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249702023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249712023-04-10 00:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249722023-04-10 00:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249732023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249742023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249752023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249762023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249772023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249782023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249792023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249802023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249812023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249822023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249832023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249842023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249852023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249862023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249872023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249882023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249892023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249902023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249912023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249922023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249932023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249942023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249952023-04-10 00:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249962023-04-10 00:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249972023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
249982023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
249992023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250002023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250012023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250022023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250032023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250042023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250052023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250062023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250072023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250082023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250092023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250102023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250112023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250122023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250132023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250142023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250152023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250162023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250172023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250182023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250192023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250202023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250212023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250222023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250232023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250242023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250252023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250262023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250272023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250282023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250292023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250302023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250312023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250322023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250332023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250342023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250352023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250362023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250372023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250382023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250392023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250402023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250412023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250422023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250432023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250442023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250452023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250462023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250472023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250482023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250492023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250502023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250512023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250522023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250532023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250542023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250552023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250562023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250572023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250582023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250592023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250602023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250612023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250622023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250632023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250642023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250652023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250662023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250672023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250682023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250692023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250702023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250712023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250722023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250732023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250742023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250752023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250762023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250772023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250782023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250792023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250802023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250812023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250822023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250832023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250842023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250852023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250862023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250872023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250882023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250892023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250902023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250912023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250922023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250932023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250942023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250952023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250962023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250972023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250982023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
250992023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251002023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251012023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251022023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251032023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251042023-04-10 00:27:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x3dfc| Process Name: C:\Windows\System32\LogonUI.exe
251052023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251062023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251072023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251082023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251092023-04-10 00:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251102023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251112023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251122023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251132023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251142023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251152023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251162023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251172023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251182023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251192023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251202023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251212023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251222023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251232023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251242023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251252023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251262023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251272023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251282023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251292023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251302023-04-10 00:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251312023-04-10 00:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251322023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251332023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251342023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251352023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251362023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251372023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251382023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251392023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251402023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251412023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251422023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251432023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251442023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251452023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251462023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251472023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251482023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251492023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251502023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251512023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251522023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251532023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251542023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251552023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251562023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251572023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251582023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251592023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251602023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251612023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251622023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251632023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251642023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251652023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251662023-04-10 00:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
251672023-04-10 00:26:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
251682023-04-10 00:26:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
251692023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251702023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251712023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251722023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251732023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251742023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251752023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251762023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251772023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251782023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251792023-04-10 00:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251802023-04-10 00:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251812023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251822023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251832023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251842023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251852023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251862023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251872023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251882023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251892023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251902023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251912023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251922023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251932023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251942023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251952023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251962023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251972023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
251982023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
251992023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252002023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252012023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252022023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252032023-04-10 00:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252042023-04-10 00:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252052023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252062023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252072023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252082023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252092023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252102023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252112023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252122023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252132023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252142023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252152023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252162023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252172023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252182023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252192023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252202023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252212023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252222023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252232023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252242023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252252023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252262023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252272023-04-10 00:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252282023-04-10 00:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252292023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252302023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252312023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252322023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252332023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252342023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252352023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252362023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252372023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252382023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252392023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252402023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252412023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252422023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252432023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252442023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252452023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252462023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252472023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252482023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252492023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252502023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252512023-04-10 00:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252522023-04-10 00:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252532023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252542023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252552023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252562023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252572023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252582023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252592023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252602023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252612023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252622023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252632023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252642023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252652023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252662023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252672023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252682023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252692023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252702023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252712023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252722023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252732023-04-10 00:22:00Microsoft-Windows-Security-Auditing4616Security State ChangeThe system time was changed.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 0x4f8c| Name: C:\Windows\System32\svchost.exe||Previous Time: ‎2023‎-‎10‎-‎04T04:22:12.326097800Z|New Time: ‎2023‎-‎10‎-‎04T04:22:12.326108200Z||This event is generated when the system time is changed. It is normal for the Windows Time Service, which runs with System privilege, to change the system time on a regular basis. Other system time changes may be indicative of attempts to tamper with the computer.
252742023-04-10 00:22:00Microsoft-Windows-Security-Auditing4616Security State ChangeThe system time was changed.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 0x4f8c| Name: C:\Windows\System32\svchost.exe||Previous Time: ‎2023‎-‎10‎-‎04T04:22:12.324616500Z|New Time: ‎2023‎-‎10‎-‎04T04:22:12.324716700Z||This event is generated when the system time is changed. It is normal for the Windows Time Service, which runs with System privilege, to change the system time on a regular basis. Other system time changes may be indicative of attempts to tamper with the computer.
252752023-04-10 00:22:00Microsoft-Windows-Security-Auditing4616Security State ChangeThe system time was changed.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 0x4f8c| Name: C:\Windows\System32\svchost.exe||Previous Time: ‎2023‎-‎10‎-‎04T04:22:11.101278500Z|New Time: ‎2023‎-‎10‎-‎04T04:22:12.323246900Z||This event is generated when the system time is changed. It is normal for the Windows Time Service, which runs with System privilege, to change the system time on a regular basis. Other system time changes may be indicative of attempts to tamper with the computer.
252762023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252772023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252782023-04-10 00:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
252792023-04-10 00:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
252802023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252812023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252822023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252832023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252842023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252852023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252862023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252872023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252882023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252892023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252902023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252912023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252922023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252932023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252942023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252952023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252962023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252972023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252982023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
252992023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253002023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253012023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253022023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253032023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253042023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253052023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253062023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253072023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253082023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253092023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253102023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253112023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253122023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253132023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253142023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253152023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253162023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253172023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253182023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253192023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253202023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253212023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253222023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253232023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253242023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253252023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253262023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253272023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253282023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253292023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253302023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253312023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253322023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253332023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253342023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253352023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253362023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253372023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253382023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253392023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253402023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253412023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253422023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253432023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253442023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253452023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253462023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253472023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253482023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253492023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253502023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253512023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253522023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253532023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253542023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253552023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253562023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253572023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253582023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253592023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253602023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253612023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253622023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253632023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253642023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253652023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253662023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253672023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253682023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253692023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253702023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253712023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253722023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253732023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253742023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253752023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253762023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253772023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253782023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253792023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253802023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253812023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253822023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253832023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253842023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253852023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253862023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253872023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253882023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253892023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253902023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253912023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253922023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253932023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253942023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253952023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253962023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253972023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253982023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
253992023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254002023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254012023-04-10 00:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254022023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254032023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254042023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254052023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254062023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254072023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254082023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254092023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254102023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254112023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254122023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254132023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254142023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254152023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254162023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254172023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254182023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254192023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254202023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254212023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254222023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254232023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254242023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254252023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254262023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254272023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254282023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254292023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254302023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254312023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254322023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254332023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254342023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254352023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254362023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254372023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254382023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254392023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254402023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254412023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254422023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254432023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254442023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254452023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254462023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254472023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254482023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254492023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254502023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254512023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254522023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254532023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254542023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254552023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254562023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
254572023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
254582023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254592023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254602023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254612023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254622023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254632023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254642023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254652023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254662023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254672023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254682023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCAD4| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254692023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254702023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254712023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254722023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254732023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254742023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254752023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254762023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254772023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254782023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254792023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254802023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254812023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254822023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254832023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254842023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254852023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254862023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254872023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254882023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254892023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254902023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254912023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254922023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254932023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254942023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254952023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254962023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254972023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254982023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
254992023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255002023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255012023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255022023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255032023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255042023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255052023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255062023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255072023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255082023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255092023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255102023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255112023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255122023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255132023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255142023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255152023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255162023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255172023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255182023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255192023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255202023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255212023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255222023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255232023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255242023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255252023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255262023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255272023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255282023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255292023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255302023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255312023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255322023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255332023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255342023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255352023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255362023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255372023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255382023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255392023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255402023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255412023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255422023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255432023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255442023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255452023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255462023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255472023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255482023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255492023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255502023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255512023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255522023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255532023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255542023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255552023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255562023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255572023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255582023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255592023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255602023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255612023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255622023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255632023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255642023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255652023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255662023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255672023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255682023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255692023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255702023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255712023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255722023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
255732023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255742023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255752023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255762023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255772023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255782023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255792023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255802023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255812023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255822023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255832023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255842023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255852023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255862023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255872023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255882023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255892023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255902023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255912023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255922023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255932023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255942023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255952023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255962023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255972023-04-10 00:21:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
255982023-04-10 00:21:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
255992023-04-10 00:21:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
256002023-04-10 00:21:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
256012023-04-10 00:21:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
256022023-04-10 00:21:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
256032023-04-10 00:21:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
256042023-04-10 00:21:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
256052023-04-10 00:21:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
256062023-04-10 00:21:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
256072023-04-10 00:21:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
256082023-04-10 00:21:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
256092023-04-10 00:21:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
256102023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256112023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256122023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256132023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256142023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256152023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256162023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256172023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256182023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256192023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256202023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256212023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256222023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256232023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256242023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256252023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256262023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256272023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256282023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256292023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256302023-04-10 00:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256312023-04-10 00:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256322023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256332023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256342023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256352023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256362023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256372023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256382023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256392023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256402023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256412023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256422023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256432023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256442023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256452023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256462023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256472023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256482023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256492023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256502023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256512023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256522023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256532023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256542023-04-10 00:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256552023-04-10 00:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256562023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256572023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256582023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256592023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256602023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256612023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256622023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256632023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256642023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256652023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256662023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256672023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256682023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256692023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256702023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256712023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256722023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256732023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256742023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256752023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256762023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256772023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256782023-04-10 00:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256792023-04-10 00:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256802023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256812023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256822023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256832023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256842023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256852023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256862023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256872023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256882023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256892023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256902023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256912023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256922023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256932023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256942023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256952023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256962023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256972023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
256982023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
256992023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257002023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257012023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257022023-04-10 00:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257032023-04-10 00:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257042023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257052023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257062023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257072023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257082023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257092023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257102023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257112023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257122023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257132023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257142023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257152023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257162023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257172023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257182023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257192023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257202023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257212023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257222023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257232023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257242023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257252023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257262023-04-10 00:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257272023-04-10 00:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257282023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257292023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257302023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257312023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257322023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257332023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257342023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257352023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257362023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257372023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257382023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257392023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257402023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257412023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257422023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257432023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257442023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257452023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257462023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257472023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257482023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257492023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257502023-04-10 00:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257512023-04-10 00:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257522023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257532023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257542023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257552023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257562023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257572023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257582023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257592023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257602023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257612023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257622023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257632023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257642023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257652023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257662023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257672023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257682023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257692023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257702023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257712023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257722023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257732023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257742023-04-10 00:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257752023-04-10 00:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257762023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257772023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257782023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257792023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257802023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257812023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257822023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257832023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257842023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257852023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257862023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257872023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257882023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257892023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257902023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257912023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257922023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257932023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257942023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257952023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257962023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257972023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
257982023-04-10 00:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
257992023-04-10 00:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258002023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258012023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258022023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258032023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258042023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258052023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258062023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258072023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258082023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258092023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258102023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258112023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258122023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258132023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258142023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258152023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258162023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258172023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258182023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258192023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258202023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258212023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258222023-04-10 00:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258232023-04-10 00:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258242023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258252023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258262023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258272023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258282023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258292023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258302023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258312023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258322023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258332023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258342023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258352023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258362023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258372023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258382023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258392023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258402023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258412023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258422023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258432023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258442023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258452023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258462023-04-10 00:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258472023-04-10 00:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258482023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258492023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258502023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258512023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258522023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258532023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258542023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258552023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258562023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258572023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258582023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258592023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258602023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258612023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258622023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258632023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258642023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258652023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258662023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258672023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258682023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258692023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258702023-04-10 00:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258712023-04-10 00:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258722023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258732023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258742023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258752023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258762023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258772023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258782023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258792023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258802023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258812023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258822023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258832023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258842023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258852023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258862023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258872023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258882023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258892023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258902023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258912023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258922023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258932023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258942023-04-10 00:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258952023-04-10 00:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258962023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258972023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
258982023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
258992023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259002023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259012023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259022023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259032023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259042023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259052023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259062023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259072023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259082023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259092023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259102023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259112023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259122023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259132023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259142023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259152023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259162023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259172023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259182023-04-10 00:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259192023-04-10 00:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259202023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259212023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259222023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259232023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259242023-04-10 00:08:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
259252023-04-10 00:08:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
259262023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259272023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259282023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259292023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259302023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259312023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259322023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259332023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259342023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259352023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259362023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259372023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259382023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259392023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259402023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259412023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259422023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259432023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259442023-04-10 00:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259452023-04-10 00:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259462023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259472023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259482023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259492023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259502023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259512023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259522023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259532023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259542023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259552023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259562023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259572023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259582023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259592023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259602023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259612023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259622023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259632023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259642023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259652023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259662023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259672023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259682023-04-10 00:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259692023-04-10 00:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259702023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259712023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259722023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259732023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259742023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259752023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259762023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259772023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259782023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259792023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259802023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259812023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259822023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259832023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259842023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259852023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259862023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259872023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259882023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259892023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259902023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259912023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259922023-04-10 00:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259932023-04-10 00:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259942023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259952023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259962023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259972023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
259982023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
259992023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260002023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260012023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260022023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260032023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260042023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260052023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260062023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260072023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260082023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260092023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260102023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260112023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260122023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260132023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260142023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260152023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260162023-04-10 00:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260172023-04-10 00:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260182023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260192023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260202023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260212023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260222023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260232023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260242023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260252023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260262023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260272023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260282023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260292023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260302023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260312023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260322023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260332023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260342023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260352023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260362023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260372023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260382023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260392023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260402023-04-10 00:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260412023-04-10 00:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260422023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260432023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260442023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260452023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260462023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260472023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260482023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260492023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260502023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260512023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260522023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260532023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260542023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260552023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260562023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260572023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260582023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260592023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260602023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260612023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260622023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260632023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260642023-04-10 00:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260652023-04-10 00:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260662023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260672023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260682023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260692023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260702023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260712023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260722023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260732023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260742023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260752023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260762023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260772023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260782023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260792023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260802023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260812023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260822023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260832023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260842023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260852023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260862023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260872023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260882023-04-10 00:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260892023-04-10 00:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260902023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260912023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260922023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260932023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260942023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260952023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260962023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260972023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
260982023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
260992023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261002023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261012023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261022023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261032023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261042023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261052023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261062023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261072023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261082023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261092023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261102023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261112023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261122023-04-10 00:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261132023-04-10 00:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261142023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261152023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261162023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261172023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261182023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261192023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261202023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261212023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261222023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261232023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261242023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261252023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261262023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261272023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261282023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261292023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261302023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261312023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261322023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261332023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261342023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261352023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261362023-04-10 00:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261372023-04-10 00:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261382023-04-10 00:00:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
261392023-04-10 00:00:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
261402023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261412023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261422023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261432023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261442023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261452023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261462023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261472023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261482023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261492023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261502023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261512023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261522023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261532023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261542023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261552023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261562023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261572023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261582023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261592023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261602023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261612023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261622023-03-10 23:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261632023-03-10 23:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261642023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261652023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261662023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261672023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261682023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261692023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261702023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261712023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261722023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261732023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261742023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261752023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261762023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261772023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261782023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261792023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261802023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261812023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261822023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261832023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261842023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261852023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261862023-03-10 23:58:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261872023-03-10 23:58:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261882023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261892023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261902023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261912023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261922023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261932023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261942023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261952023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261962023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261972023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
261982023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
261992023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262002023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262012023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262022023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262032023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262042023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262052023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262062023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262072023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262082023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262092023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262102023-03-10 23:57:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262112023-03-10 23:57:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262122023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262132023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262142023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262152023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262162023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262172023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262182023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262192023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262202023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262212023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262222023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262232023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262242023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262252023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262262023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262272023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262282023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262292023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262302023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262312023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262322023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262332023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262342023-03-10 23:56:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262352023-03-10 23:56:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262362023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262372023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262382023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262392023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262402023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262412023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262422023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262432023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262442023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262452023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262462023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262472023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262482023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262492023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262502023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262512023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262522023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262532023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262542023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262552023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262562023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262572023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262582023-03-10 23:55:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262592023-03-10 23:55:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262602023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262612023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262622023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262632023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262642023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262652023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262662023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262672023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262682023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262692023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262702023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262712023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262722023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262732023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262742023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262752023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262762023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262772023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262782023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262792023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262802023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262812023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262822023-03-10 23:54:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262832023-03-10 23:54:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262842023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262852023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262862023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262872023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262882023-03-10 23:53:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
262892023-03-10 23:53:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
262902023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262912023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262922023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262932023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262942023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262952023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262962023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262972023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
262982023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
262992023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263002023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263012023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263022023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263032023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263042023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263052023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263062023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263072023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263082023-03-10 23:53:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263092023-03-10 23:53:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263102023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263112023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263122023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263132023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263142023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263152023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263162023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263172023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263182023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263192023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263202023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263212023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263222023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263232023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263242023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263252023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263262023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263272023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263282023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263292023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263302023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263312023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263322023-03-10 23:52:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263332023-03-10 23:52:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263342023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263352023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263362023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263372023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263382023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263392023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263402023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263412023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263422023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263432023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263442023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263452023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263462023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263472023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263482023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263492023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263502023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263512023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263522023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263532023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263542023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263552023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263562023-03-10 23:51:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263572023-03-10 23:51:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263582023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263592023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263602023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263612023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263622023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263632023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263642023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263652023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263662023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263672023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263682023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263692023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263702023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263712023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263722023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263732023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263742023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263752023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263762023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263772023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263782023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263792023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263802023-03-10 23:50:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263812023-03-10 23:50:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263822023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263832023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263842023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263852023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263862023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263872023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263882023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263892023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263902023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263912023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263922023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263932023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263942023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263952023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263962023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263972023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
263982023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
263992023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264002023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264012023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264022023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264032023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264042023-03-10 23:49:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264052023-03-10 23:49:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264062023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264072023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264082023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264092023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264102023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264112023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264122023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264132023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264142023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264152023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264162023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264172023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264182023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264192023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264202023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264212023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264222023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264232023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264242023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264252023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264262023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264272023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264282023-03-10 23:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264292023-03-10 23:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264302023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264312023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264322023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264332023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264342023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264352023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264362023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264372023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264382023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264392023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264402023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264412023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264422023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264432023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264442023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264452023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264462023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264472023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264482023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264492023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264502023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264512023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264522023-03-10 23:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264532023-03-10 23:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264542023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264552023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264562023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264572023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264582023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264592023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264602023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264612023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264622023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264632023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264642023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264652023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264662023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264672023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264682023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264692023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264702023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264712023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264722023-03-10 23:46:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
264732023-03-10 23:46:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
264742023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264752023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264762023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264772023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264782023-03-10 23:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264792023-03-10 23:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264802023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264812023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264822023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264832023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264842023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264852023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264862023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264872023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264882023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264892023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264902023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264912023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264922023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264932023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264942023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264952023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264962023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264972023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
264982023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
264992023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265002023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265012023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265022023-03-10 23:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265032023-03-10 23:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265042023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265052023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265062023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265072023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265082023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265092023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265102023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265112023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265122023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265132023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265142023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265152023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265162023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265172023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265182023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265192023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265202023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265212023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265222023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265232023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265242023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265252023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265262023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265272023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265282023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265292023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265302023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265312023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265322023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265332023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265342023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265352023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265362023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265372023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265382023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265392023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265402023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265412023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265422023-03-10 23:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265432023-03-10 23:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265442023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265452023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265462023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265472023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265482023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265492023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265502023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265512023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265522023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265532023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265542023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265552023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265562023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265572023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265582023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265592023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265602023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265612023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265622023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265632023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265642023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265652023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265662023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265672023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265682023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265692023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265702023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265712023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265722023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265732023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265742023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265752023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265762023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265772023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265782023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265792023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265802023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265812023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265822023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265832023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265842023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265852023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265862023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265872023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265882023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265892023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265902023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265912023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265922023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265932023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265942023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265952023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265962023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265972023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
265982023-03-10 23:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
265992023-03-10 23:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266002023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266012023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266022023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266032023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266042023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266052023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266062023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266072023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266082023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266092023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266102023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266112023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266122023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266132023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266142023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266152023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266162023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266172023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266182023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266192023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266202023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266212023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266222023-03-10 23:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266232023-03-10 23:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266242023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266252023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266262023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266272023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266282023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266292023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266302023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266312023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266322023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266332023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266342023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266352023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266362023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266372023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266382023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266392023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266402023-03-10 23:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
266412023-03-10 23:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
266422023-03-10 23:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
266432023-03-10 23:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
266442023-03-10 23:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
266452023-03-10 23:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
266462023-03-10 23:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
266472023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266482023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266492023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266502023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266512023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266522023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266532023-03-10 23:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266542023-03-10 23:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266552023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266562023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266572023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266582023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266592023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266602023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266612023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266622023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266632023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266642023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266652023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266662023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266672023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266682023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266692023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266702023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266712023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266722023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266732023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266742023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266752023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266762023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266772023-03-10 23:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266782023-03-10 23:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266792023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266802023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266812023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266822023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266832023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266842023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266852023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266862023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266872023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266882023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266892023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266902023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266912023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266922023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266932023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266942023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266952023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266962023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266972023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
266982023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
266992023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267002023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267012023-03-10 23:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267022023-03-10 23:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267032023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267042023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267052023-03-10 23:38:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
267062023-03-10 23:38:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
267072023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267082023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267092023-03-10 23:38:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
267102023-03-10 23:38:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
267112023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267122023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267132023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267142023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267152023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267162023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267172023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267182023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267192023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267202023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267212023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267222023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267232023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267242023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267252023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267262023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267272023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267282023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267292023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267302023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267312023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267322023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267332023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267342023-03-10 23:38:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
267352023-03-10 23:38:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
267362023-03-10 23:38:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
267372023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267382023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267392023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267402023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267412023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267422023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267432023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267442023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267452023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267462023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267472023-03-10 23:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267482023-03-10 23:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267492023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267502023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267512023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267522023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267532023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267542023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267552023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267562023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267572023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267582023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267592023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267602023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267612023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267622023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267632023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267642023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267652023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267662023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267672023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267682023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267692023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267702023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267712023-03-10 23:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267722023-03-10 23:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267732023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267742023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267752023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267762023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267772023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267782023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267792023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267802023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267812023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267822023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267832023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267842023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267852023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267862023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267872023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267882023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267892023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267902023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267912023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267922023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267932023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267942023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267952023-03-10 23:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267962023-03-10 23:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267972023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
267982023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
267992023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268002023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268012023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268022023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268032023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268042023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268052023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268062023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268072023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268082023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268092023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268102023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268112023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268122023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268132023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268142023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268152023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268162023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268172023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268182023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268192023-03-10 23:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268202023-03-10 23:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268212023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268222023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268232023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268242023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268252023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268262023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268272023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268282023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268292023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268302023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268312023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268322023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268332023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268342023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268352023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268362023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268372023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268382023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268392023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268402023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268412023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268422023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268432023-03-10 23:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268442023-03-10 23:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268452023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268462023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268472023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268482023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268492023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268502023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268512023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268522023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268532023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268542023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268552023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268562023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268572023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268582023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268592023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268602023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268612023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268622023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268632023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268642023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268652023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268662023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268672023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268682023-03-10 23:33:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
268692023-03-10 23:33:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
268702023-03-10 23:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268712023-03-10 23:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268722023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268732023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268742023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268752023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268762023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268772023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268782023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268792023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268802023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268812023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268822023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268832023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268842023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268852023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268862023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268872023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268882023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268892023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268902023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268912023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268922023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268932023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268942023-03-10 23:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268952023-03-10 23:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268962023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268972023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
268982023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
268992023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269002023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269012023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269022023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269032023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269042023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269052023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269062023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269072023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269082023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269092023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269102023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269112023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269122023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269132023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269142023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269152023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269162023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269172023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269182023-03-10 23:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269192023-03-10 23:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269202023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269212023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269222023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269232023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269242023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269252023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269262023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269272023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269282023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269292023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269302023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269312023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269322023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269332023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269342023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269352023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269362023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269372023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269382023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269392023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269402023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269412023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269422023-03-10 23:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269432023-03-10 23:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269442023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269452023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269462023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269472023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269482023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269492023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269502023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269512023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269522023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269532023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269542023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269552023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269562023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269572023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269582023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269592023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269602023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269612023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269622023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269632023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269642023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269652023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269662023-03-10 23:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269672023-03-10 23:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269682023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269692023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269702023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269712023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269722023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269732023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269742023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269752023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269762023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269772023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269782023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269792023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269802023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269812023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269822023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269832023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269842023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269852023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269862023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269872023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269882023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269892023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269902023-03-10 23:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269912023-03-10 23:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269922023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269932023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269942023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269952023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269962023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269972023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
269982023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
269992023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270002023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270012023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270022023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270032023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270042023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270052023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270062023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270072023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270082023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270092023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270102023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270112023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270122023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270132023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270142023-03-10 23:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270152023-03-10 23:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270162023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270172023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270182023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270192023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270202023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270212023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270222023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270232023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270242023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270252023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270262023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270272023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270282023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270292023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270302023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270312023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270322023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270332023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270342023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270352023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270362023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270372023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270382023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270392023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270402023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270412023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270422023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270432023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270442023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270452023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270462023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270472023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270482023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270492023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270502023-03-10 23:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
270512023-03-10 23:26:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
270522023-03-10 23:26:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
270532023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270542023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270552023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270562023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270572023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270582023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270592023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270602023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270612023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270622023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270632023-03-10 23:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270642023-03-10 23:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270652023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270662023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270672023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270682023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270692023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270702023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270712023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270722023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270732023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270742023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270752023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270762023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270772023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270782023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270792023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270802023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270812023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270822023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270832023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270842023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270852023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270862023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270872023-03-10 23:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270882023-03-10 23:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270892023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270902023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270912023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270922023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270932023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270942023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270952023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270962023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270972023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
270982023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
270992023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271002023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271012023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271022023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271032023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271042023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271052023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271062023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271072023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271082023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271092023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271102023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271112023-03-10 23:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271122023-03-10 23:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271132023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271142023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271152023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271162023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271172023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271182023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271192023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271202023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271212023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271222023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271232023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271242023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271252023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271262023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271272023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271282023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271292023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271302023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271312023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271322023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271332023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271342023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271352023-03-10 23:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271362023-03-10 23:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271372023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271382023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271392023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271402023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271412023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271422023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271432023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271442023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271452023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271462023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
271472023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271482023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271492023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271502023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271512023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271522023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271532023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271542023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271552023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271562023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271572023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271582023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271592023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271602023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271612023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271622023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271632023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271642023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271652023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271662023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271672023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271682023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271692023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271702023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271712023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271722023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271732023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271742023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271752023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271762023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271772023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271782023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271792023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271802023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271812023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271822023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271832023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271842023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271852023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271862023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271872023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271882023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271892023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271902023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271912023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271922023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271932023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271942023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271952023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271962023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
271972023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_api.application| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271982023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
271992023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_office.net| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272002023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272012023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272022023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272032023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272042023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272052023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272062023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272072023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272082023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272092023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272102023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272112023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272122023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272132023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272142023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272152023-03-10 23:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
272162023-03-10 23:22:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
272172023-03-10 23:22:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
272182023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272192023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272202023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272212023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272222023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272232023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272242023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272252023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272262023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272272023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272282023-03-10 23:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272292023-03-10 23:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272302023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272312023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272322023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272332023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272342023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272352023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272362023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272372023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272382023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272392023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272402023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272412023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272422023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272432023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272442023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272452023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272462023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272472023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272482023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272492023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272502023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272512023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272522023-03-10 23:21:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272532023-03-10 23:21:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272542023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272552023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272562023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272572023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272582023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272592023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272602023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272612023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272622023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272632023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272642023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272652023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272662023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272672023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272682023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272692023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272702023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272712023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272722023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272732023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272742023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272752023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272762023-03-10 23:20:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272772023-03-10 23:20:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272782023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272792023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272802023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272812023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272822023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272832023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272842023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272852023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272862023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272872023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272882023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272892023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272902023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272912023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272922023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272932023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272942023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272952023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272962023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272972023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
272982023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
272992023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273002023-03-10 23:19:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273012023-03-10 23:19:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273022023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273032023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273042023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273052023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273062023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273072023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273082023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273092023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273102023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273112023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273122023-03-10 23:18:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
273132023-03-10 23:18:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
273142023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273152023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273162023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273172023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273182023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273192023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273202023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273212023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273222023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273232023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273242023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273252023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273262023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273272023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273282023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273292023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273302023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273312023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273322023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273332023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273342023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273352023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273362023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273372023-03-10 23:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
273382023-03-10 23:18:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
273392023-03-10 23:18:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
273402023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273412023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273422023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273432023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273442023-03-10 23:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273452023-03-10 23:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273462023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273472023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273482023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273492023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273502023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273512023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273522023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273532023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273542023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273552023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273562023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273572023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273582023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273592023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273602023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273612023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273622023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273632023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273642023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273652023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273662023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273672023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273682023-03-10 23:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273692023-03-10 23:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273702023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273712023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273722023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273732023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273742023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273752023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273762023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273772023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273782023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273792023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273802023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273812023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273822023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273832023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273842023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273852023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273862023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273872023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273882023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273892023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273902023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273912023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273922023-03-10 23:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273932023-03-10 23:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273942023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273952023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273962023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273972023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
273982023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
273992023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274002023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274012023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274022023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274032023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274042023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274052023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274062023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274072023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274082023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274092023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274102023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274112023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274122023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274132023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274142023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274152023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274162023-03-10 23:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274172023-03-10 23:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274182023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274192023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274202023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274212023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274222023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274232023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274242023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274252023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274262023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274272023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274282023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274292023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274302023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274312023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274322023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274332023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274342023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274352023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274362023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274372023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274382023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274392023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274402023-03-10 23:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274412023-03-10 23:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274422023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274432023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274442023-03-10 23:13:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
274452023-03-10 23:13:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
274462023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274472023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274482023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274492023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274502023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274512023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274522023-03-10 23:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
274532023-03-10 23:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
274542023-03-10 23:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
274552023-03-10 23:13:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
274562023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274572023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274582023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274592023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274602023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274612023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274622023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274632023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274642023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274652023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274662023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274672023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274682023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274692023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274702023-03-10 23:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274712023-03-10 23:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274722023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274732023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274742023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274752023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274762023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274772023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274782023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274792023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274802023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274812023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274822023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274832023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274842023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274852023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274862023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274872023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274882023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274892023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274902023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274912023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274922023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274932023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274942023-03-10 23:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274952023-03-10 23:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274962023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
274972023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
274982023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
274992023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275002023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275012023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275022023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275032023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275042023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275052023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275062023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275072023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275082023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275092023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275102023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275112023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275122023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275132023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275142023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275152023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275162023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275172023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275182023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275192023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275202023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275212023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275222023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275232023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275242023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275252023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275262023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275272023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275282023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275292023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275302023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275312023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275322023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275332023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275342023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275352023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275362023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275372023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275382023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275392023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275402023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275412023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275422023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275432023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275442023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275452023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275462023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275472023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275482023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275492023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275502023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275512023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275522023-03-10 23:11:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
275532023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275542023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275552023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275562023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275572023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275582023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275592023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275602023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275612023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275622023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275632023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275642023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275652023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275662023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275672023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275682023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275692023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275702023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275712023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275722023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275732023-03-10 23:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275742023-03-10 23:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275752023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275762023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275772023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275782023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275792023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275802023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275812023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275822023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275832023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275842023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275852023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275862023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275872023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275882023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275892023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275902023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275912023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275922023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275932023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275942023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275952023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275962023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275972023-03-10 23:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
275982023-03-10 23:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
275992023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276002023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276012023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276022023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276032023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276042023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276052023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276062023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276072023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276082023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276092023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276102023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276112023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276122023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276132023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276142023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276152023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276162023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276172023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276182023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276192023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276202023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276212023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276222023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276232023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276242023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276252023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276262023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276272023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276282023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276292023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276302023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276312023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276322023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276332023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276342023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276352023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276362023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276372023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276382023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276392023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276402023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276412023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276422023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276432023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276442023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276452023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276462023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276472023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276482023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276492023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276502023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276512023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276522023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276532023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276542023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276552023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276562023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276572023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276582023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276592023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276602023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276612023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276622023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276632023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276642023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276652023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276662023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276672023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276682023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276692023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276702023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276712023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276722023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276732023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276742023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276752023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276762023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276772023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276782023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276792023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276802023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276812023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276822023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276832023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276842023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276852023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276862023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276872023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276882023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276892023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276902023-03-10 23:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
276912023-03-10 23:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
276922023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276932023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276942023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276952023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276962023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276972023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276982023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
276992023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277002023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277012023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277022023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277032023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277042023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277052023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277062023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277072023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277082023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277092023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277102023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277112023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277122023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277132023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277142023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277152023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277162023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277172023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277182023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277192023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277202023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277212023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277222023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277232023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277242023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277252023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277262023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277272023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277282023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277292023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277302023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277312023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277322023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277332023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277342023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277352023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277362023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277372023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277382023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277392023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277402023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277412023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277422023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277432023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277442023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277452023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277462023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277472023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277482023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277492023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277502023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277512023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277522023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277532023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277542023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277552023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277562023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277572023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277582023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277592023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277602023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277612023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277622023-03-10 23:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277632023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277642023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277652023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277662023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277672023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277682023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277692023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277702023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277712023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277722023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277732023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277742023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277752023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277762023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277772023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277782023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277792023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277802023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277812023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277822023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277832023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277842023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277852023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277862023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277872023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277882023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277892023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277902023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277912023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277922023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277932023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277942023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277952023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277962023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277972023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277982023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
277992023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278002023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278012023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278022023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278032023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278042023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278052023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278062023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278072023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278082023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278092023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278102023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278112023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278122023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278132023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278142023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278152023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278162023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278172023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278182023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278192023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278202023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278212023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278222023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278232023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278242023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
278252023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
278262023-03-10 23:08:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x2EF224B||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
278272023-03-10 23:08:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x2EF3987||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
278282023-03-10 23:08:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x2EF22B1||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
278292023-03-10 23:08:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x2EF3AF4||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
278302023-03-10 23:08:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2EF3987||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
278312023-03-10 23:08:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2EF3AF4| Linked Logon ID: 0x2EF3987| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
278322023-03-10 23:08:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2EF3987| Linked Logon ID: 0x2EF3AF4| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
278332023-03-10 23:08:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
278342023-03-10 23:08:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
278352023-03-10 23:08:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
278362023-03-10 23:08:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
278372023-03-10 23:08:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2EF224B||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
278382023-03-10 23:08:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2EF22B1| Linked Logon ID: 0x2EF224B| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
278392023-03-10 23:08:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2EF224B| Linked Logon ID: 0x2EF22B1| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
278402023-03-10 23:08:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
278412023-03-10 23:08:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
278422023-03-10 23:08:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
278432023-03-10 23:08:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
278442023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278452023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278462023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278472023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278482023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278492023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278502023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278512023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278522023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278532023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278542023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278552023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278562023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278572023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278582023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278592023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278602023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278612023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278622023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278632023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278642023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278652023-03-10 23:08:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
278662023-03-10 23:08:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
278672023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
278682023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
278692023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
278702023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
278712023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
278722023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
278732023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
278742023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
278752023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
278762023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
278772023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
278782023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
278792023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
278802023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
278812023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
278822023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
278832023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
278842023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
278852023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
278862023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
278872023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278882023-03-10 23:08:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
278892023-03-10 23:08:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
278902023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278912023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278922023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278932023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278942023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278952023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278962023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278972023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278982023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
278992023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
279002023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
279012023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
279022023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
279032023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
279042023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
279052023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
279062023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
279072023-03-10 23:08:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
279082023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279092023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279102023-03-10 23:08:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
279112023-03-10 23:08:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
279122023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279132023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279142023-03-10 23:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279152023-03-10 23:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279162023-03-10 23:08:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
279172023-03-10 23:08:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
279182023-03-10 23:06:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
279192023-03-10 23:06:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
279202023-03-10 23:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279212023-03-10 23:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279222023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279232023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279242023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279252023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279262023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279272023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279282023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279292023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279302023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279312023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279322023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279332023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279342023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279352023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279362023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279372023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279382023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279392023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279402023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279412023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279422023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279432023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279442023-03-10 23:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279452023-03-10 23:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279462023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279472023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279482023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279492023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279502023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279512023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279522023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279532023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279542023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279552023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279562023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279572023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279582023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279592023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279602023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279612023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279622023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279632023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279642023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279652023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279662023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279672023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279682023-03-10 23:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279692023-03-10 23:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279702023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279712023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279722023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279732023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279742023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279752023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279762023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279772023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279782023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279792023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279802023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279812023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279822023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279832023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279842023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279852023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279862023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279872023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279882023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279892023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279902023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279912023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279922023-03-10 23:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279932023-03-10 23:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279942023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279952023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279962023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279972023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
279982023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
279992023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280002023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280012023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280022023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280032023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280042023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280052023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280062023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280072023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280082023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280092023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280102023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280112023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280122023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280132023-03-10 23:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
280142023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280152023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280162023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280172023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280182023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280192023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280202023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280212023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280222023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280232023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280242023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280252023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280262023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280272023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280282023-03-10 23:02:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x2c3c| Process Name: C:\Windows\System32\LogonUI.exe
280292023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280302023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280312023-03-10 23:02:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
280322023-03-10 23:02:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
280332023-03-10 23:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280342023-03-10 23:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280352023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280362023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280372023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280382023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280392023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280402023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280412023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280422023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280432023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280442023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280452023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280462023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280472023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280482023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280492023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280502023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280512023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280522023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280532023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280542023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280552023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280562023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280572023-03-10 23:01:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280582023-03-10 23:01:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280592023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280602023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280612023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280622023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280632023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280642023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280652023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280662023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280672023-03-10 23:00:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
280682023-03-10 23:00:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
280692023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280702023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280712023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280722023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280732023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280742023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280752023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280762023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280772023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280782023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280792023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280802023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280812023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280822023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280832023-03-10 23:00:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280842023-03-10 23:00:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280852023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280862023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280872023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280882023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280892023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280902023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280912023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280922023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280932023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280942023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280952023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
280962023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
280972023-03-10 22:59:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
280982023-03-10 22:59:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
280992023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281002023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281012023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281022023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281032023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281042023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281052023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281062023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281072023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281082023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281092023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281102023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281112023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281122023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281132023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281142023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
281152023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
281162023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281172023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281182023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281192023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281202023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281212023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281222023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281232023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281242023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281252023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281262023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281272023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281282023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281292023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281302023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281312023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281322023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281332023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281342023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281352023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281362023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281372023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
281382023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
281392023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281402023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281412023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281422023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281432023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281442023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281452023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281462023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281472023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281482023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281492023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281502023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281512023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281522023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281532023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281542023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281552023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281562023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281572023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281582023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281592023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281602023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
281612023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
281622023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281632023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281642023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281652023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281662023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281672023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281682023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281692023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281702023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281712023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281722023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281732023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281742023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281752023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281762023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281772023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281782023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281792023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281802023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281812023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281822023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281832023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281842023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281852023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281862023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281872023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281882023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281892023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281902023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281912023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281922023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281932023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281942023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281952023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281962023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281972023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281982023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
281992023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282002023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282012023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282022023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282032023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282042023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282052023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282062023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282072023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282082023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282092023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282102023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282112023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282122023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282132023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282142023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282152023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282162023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282172023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282182023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282192023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282202023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282212023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282222023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282232023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282242023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282252023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282262023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282272023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282282023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282292023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
282302023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
282312023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282322023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282332023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282342023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282352023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282362023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282372023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282382023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282392023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282402023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282412023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282422023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282432023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282442023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282452023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282462023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282472023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282482023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282492023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282502023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282512023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282522023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282532023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282542023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282552023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282562023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282572023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282582023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282592023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282602023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282612023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282622023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282632023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282642023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282652023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282662023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282672023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282682023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282692023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282702023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282712023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282722023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282732023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282742023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282752023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282762023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282772023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282782023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282792023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282802023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282812023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282822023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282832023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282842023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282852023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282862023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282872023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282882023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282892023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282902023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282912023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282922023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282932023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282942023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282952023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282962023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282972023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
282982023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
282992023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
283002023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283012023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283022023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283032023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283042023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283052023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283062023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283072023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283082023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283092023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283102023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283112023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283122023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283132023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283142023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283152023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283162023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283172023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283182023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283192023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283202023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283212023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283222023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283232023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283242023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283252023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283262023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283272023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283282023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283292023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283302023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283312023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283322023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283332023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283342023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283352023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283362023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283372023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283382023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283392023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283402023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283412023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283422023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283432023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283442023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283452023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283462023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283472023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283482023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283492023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283502023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283512023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283522023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283532023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283542023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283552023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283562023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283572023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283582023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283592023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283602023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283612023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283622023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283632023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283642023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283652023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283662023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283672023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283682023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283692023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283702023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283712023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283722023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283732023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283742023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283752023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283762023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283772023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283782023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283792023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283802023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283812023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283822023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283832023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283842023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283852023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283862023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283872023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283882023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283892023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283902023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283912023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283922023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283932023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283942023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283952023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283962023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283972023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283982023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
283992023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284002023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284012023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284022023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284032023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284042023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284052023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284062023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284072023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284082023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284092023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284102023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284112023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284122023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284132023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284142023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284152023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284162023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284172023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284182023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284192023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284202023-03-10 22:59:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
284212023-03-10 22:59:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
284222023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284232023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284242023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284252023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284262023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284272023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284282023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284292023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284302023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284312023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284322023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284332023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284342023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284352023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284362023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284372023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284382023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284392023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284402023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284412023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284422023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284432023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284442023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284452023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284462023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284472023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284482023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284492023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284502023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284512023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284522023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284532023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284542023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284552023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284562023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284572023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284582023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284592023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284602023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284612023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284622023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284632023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284642023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284652023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284662023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284672023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284682023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284692023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284702023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284712023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284722023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284732023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284742023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284752023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284762023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284772023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284782023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284792023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284802023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284812023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284822023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284832023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284842023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284852023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284862023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284872023-03-10 22:59:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
284882023-03-10 22:59:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284892023-03-10 22:59:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284902023-03-10 22:59:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
284912023-03-10 22:59:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
284922023-03-10 22:59:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
284932023-03-10 22:59:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
284942023-03-10 22:48:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
284952023-03-10 22:48:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
284962023-03-10 22:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
284972023-03-10 22:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
284982023-03-10 22:48:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x2c3c| Process Name: C:\Windows\System32\LogonUI.exe
284992023-03-10 22:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285002023-03-10 22:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285012023-03-10 22:48:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
285022023-03-10 22:48:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
285032023-03-10 22:48:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
285042023-03-10 22:48:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
285052023-03-10 22:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285062023-03-10 22:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285072023-03-10 22:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285082023-03-10 22:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285092023-03-10 22:48:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285102023-03-10 22:48:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285112023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285122023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285132023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285142023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285152023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285162023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285172023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285182023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285192023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285202023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285212023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285222023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285232023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285242023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285252023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285262023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285272023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285282023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285292023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285302023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285312023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285322023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285332023-03-10 22:47:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285342023-03-10 22:47:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285352023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285362023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285372023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285382023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285392023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285402023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285412023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285422023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285432023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285442023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285452023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285462023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285472023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285482023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285492023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285502023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285512023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285522023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285532023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285542023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285552023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285562023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285572023-03-10 22:46:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285582023-03-10 22:46:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285592023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285602023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285612023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285622023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285632023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285642023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285652023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285662023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285672023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285682023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285692023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285702023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285712023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285722023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285732023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285742023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285752023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285762023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285772023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285782023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285792023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285802023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285812023-03-10 22:45:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285822023-03-10 22:45:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285832023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285842023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285852023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285862023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285872023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285882023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285892023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285902023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285912023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285922023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285932023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285942023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285952023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285962023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285972023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
285982023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
285992023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286002023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286012023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286022023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286032023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286042023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286052023-03-10 22:44:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286062023-03-10 22:44:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286072023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286082023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286092023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286102023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286112023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286122023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286132023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286142023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286152023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286162023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286172023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286182023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286192023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286202023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286212023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286222023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286232023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286242023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286252023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286262023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286272023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286282023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286292023-03-10 22:43:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286302023-03-10 22:43:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286312023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286322023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286332023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286342023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286352023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286362023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286372023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286382023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286392023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286402023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286412023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286422023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286432023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286442023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286452023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286462023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286472023-03-10 22:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286482023-03-10 22:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286492023-03-10 22:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286502023-03-10 22:42:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286512023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286522023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286532023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286542023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286552023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286562023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286572023-03-10 22:42:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286582023-03-10 22:42:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286592023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286602023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286612023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286622023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286632023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286642023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286652023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286662023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286672023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286682023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286692023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286702023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286712023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
286722023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
286732023-03-10 22:41:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
286742023-03-10 22:41:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
286752023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286762023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286772023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286782023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286792023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286802023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286812023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286822023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286832023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286842023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286852023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286862023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286872023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286882023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286892023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286902023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286912023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286922023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286932023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286942023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286952023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286962023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286972023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286982023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
286992023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287002023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287012023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287022023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287032023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287042023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287052023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287062023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287072023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287082023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287092023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287102023-03-10 22:41:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
287112023-03-10 22:41:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
287122023-03-10 22:41:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
287132023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287142023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287152023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287162023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287172023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287182023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287192023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287202023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287212023-03-10 22:41:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287222023-03-10 22:41:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287232023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287242023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287252023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287262023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287272023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287282023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287292023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287302023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287312023-03-10 22:40:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
287322023-03-10 22:40:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
287332023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287342023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287352023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287362023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287372023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287382023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287392023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287402023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287412023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287422023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287432023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287442023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287452023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287462023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287472023-03-10 22:40:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287482023-03-10 22:40:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287492023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287502023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287512023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287522023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287532023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287542023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287552023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287562023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287572023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287582023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287592023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287602023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287612023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287622023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287632023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287642023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287652023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287662023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287672023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287682023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287692023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287702023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287712023-03-10 22:39:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287722023-03-10 22:39:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287732023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287742023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287752023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287762023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287772023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287782023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287792023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287802023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287812023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287822023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287832023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287842023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287852023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287862023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287872023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287882023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287892023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287902023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287912023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287922023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287932023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287942023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287952023-03-10 22:38:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287962023-03-10 22:38:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287972023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
287982023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
287992023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288002023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288012023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288022023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288032023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288042023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288052023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288062023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288072023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288082023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288092023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288102023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288112023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288122023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288132023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288142023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288152023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288162023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288172023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288182023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288192023-03-10 22:37:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288202023-03-10 22:37:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288212023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288222023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288232023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288242023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288252023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288262023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288272023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288282023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288292023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288302023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288312023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288322023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288332023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288342023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288352023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288362023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288372023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288382023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288392023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288402023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288412023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288422023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288432023-03-10 22:36:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288442023-03-10 22:36:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288452023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288462023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288472023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288482023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288492023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288502023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288512023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288522023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288532023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288542023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288552023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288562023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288572023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288582023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288592023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288602023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288612023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288622023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288632023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288642023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288652023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288662023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288672023-03-10 22:35:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288682023-03-10 22:35:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288692023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288702023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288712023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288722023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288732023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288742023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288752023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288762023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288772023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288782023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288792023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288802023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288812023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288822023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288832023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288842023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288852023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288862023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288872023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288882023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288892023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288902023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288912023-03-10 22:34:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288922023-03-10 22:34:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288932023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288942023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288952023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288962023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288972023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
288982023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
288992023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289002023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289012023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289022023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289032023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289042023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289052023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289062023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289072023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289082023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289092023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289102023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289112023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289122023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289132023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289142023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289152023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289162023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289172023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289182023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289192023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289202023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289212023-03-10 22:33:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
289222023-03-10 22:33:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
289232023-03-10 22:33:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
289242023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289252023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289262023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289272023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289282023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289292023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289302023-03-10 22:33:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289312023-03-10 22:33:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289322023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289332023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289342023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289352023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289362023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289372023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289382023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289392023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289402023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289412023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289422023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289432023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289442023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289452023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289462023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289472023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289482023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289492023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289502023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289512023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289522023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289532023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289542023-03-10 22:32:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289552023-03-10 22:32:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289562023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289572023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289582023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289592023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289602023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289612023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289622023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289632023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289642023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289652023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289662023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289672023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289682023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289692023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289702023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289712023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289722023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289732023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289742023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289752023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289762023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289772023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289782023-03-10 22:31:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289792023-03-10 22:31:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289802023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289812023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289822023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289832023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289842023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289852023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289862023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289872023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289882023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289892023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289902023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289912023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289922023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289932023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289942023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289952023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289962023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289972023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
289982023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
289992023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290002023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290012023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290022023-03-10 22:30:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290032023-03-10 22:30:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290042023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290052023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290062023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290072023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290082023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290092023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290102023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290112023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290122023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290132023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290142023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290152023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290162023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290172023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290182023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290192023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290202023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290212023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290222023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290232023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290242023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290252023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290262023-03-10 22:29:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290272023-03-10 22:29:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290282023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290292023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290302023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290312023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290322023-03-10 22:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290332023-03-10 22:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290342023-03-10 22:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290352023-03-10 22:28:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290362023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290372023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290382023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290392023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290402023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290412023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290422023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290432023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290442023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290452023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290462023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290472023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290482023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290492023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290502023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290512023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290522023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290532023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290542023-03-10 22:28:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290552023-03-10 22:28:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290562023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290572023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290582023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290592023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290602023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290612023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290622023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290632023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290642023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290652023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290662023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290672023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290682023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290692023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290702023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290712023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290722023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290732023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290742023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290752023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290762023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290772023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290782023-03-10 22:27:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290792023-03-10 22:27:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290802023-03-10 22:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290812023-03-10 22:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290822023-03-10 22:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290832023-03-10 22:27:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290842023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290852023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290862023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
290872023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
290882023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290892023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290902023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290912023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290922023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290932023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290942023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290952023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290962023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290972023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290982023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
290992023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291002023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291012023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291022023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291032023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291042023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291052023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291062023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291072023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291082023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291092023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291102023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291112023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291122023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291132023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291142023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291152023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291162023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291172023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291182023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291192023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291202023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291212023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291222023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291232023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291242023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291252023-03-10 22:26:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291262023-03-10 22:26:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
291272023-03-10 22:26:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
291282023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291292023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291302023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291312023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291322023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291332023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291342023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291352023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291362023-03-10 22:26:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291372023-03-10 22:26:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291382023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291392023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291402023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291412023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291422023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291432023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291442023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291452023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291462023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291472023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291482023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291492023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291502023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291512023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291522023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291532023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291542023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291552023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291562023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291572023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291582023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291592023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291602023-03-10 22:25:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291612023-03-10 22:25:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291622023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291632023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291642023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291652023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291662023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291672023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291682023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291692023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291702023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291712023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291722023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291732023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291742023-03-10 22:24:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
291752023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291762023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291772023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291782023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291792023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291802023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291812023-03-10 22:24:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
291822023-03-10 22:24:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
291832023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
291842023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
291852023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291862023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291872023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291882023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291892023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291902023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291912023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291922023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291932023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291942023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291952023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291962023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291972023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291982023-03-10 22:24:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
291992023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
292002023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
292012023-03-10 22:24:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
292022023-03-10 22:24:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
292032023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
292042023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
292052023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
292062023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
292072023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292082023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292092023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292102023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292112023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292122023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292132023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292142023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292152023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292162023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292172023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292182023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292192023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292202023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292212023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292222023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292232023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292242023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292252023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292262023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292272023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292282023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292292023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292302023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292312023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292322023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292332023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292342023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292352023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292362023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292372023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292382023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292392023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292402023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292412023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292422023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292432023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292442023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292452023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292462023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292472023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292482023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292492023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292502023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292512023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292522023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292532023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292542023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292552023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292562023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292572023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292582023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292592023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292602023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292612023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292622023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
292632023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
292642023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292652023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292662023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292672023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292682023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292692023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292702023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292712023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292722023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292732023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292742023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292752023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292762023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292772023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292782023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292792023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292802023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292812023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292822023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292832023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292842023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292852023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292862023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292872023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292882023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292892023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292902023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292912023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292922023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292932023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292942023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292952023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292962023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292972023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292982023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
292992023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293002023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293012023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293022023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293032023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293042023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293052023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293062023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293072023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293082023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293092023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293102023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293112023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293122023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293132023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293142023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293152023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293162023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293172023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293182023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293192023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
293202023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
293212023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
293222023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
293232023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
293242023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
293252023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
293262023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
293272023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
293282023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
293292023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
293302023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
293312023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
293322023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
293332023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
293342023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
293352023-03-10 22:23:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
293362023-03-10 22:23:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
293372023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293382023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293392023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293402023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293412023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293422023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293432023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293442023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293452023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293462023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293472023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293482023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293492023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293502023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293512023-03-10 22:23:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
293522023-03-10 22:23:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
293532023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293542023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293552023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293562023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293572023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293582023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293592023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293602023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293612023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293622023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293632023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293642023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293652023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293662023-03-10 22:23:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293672023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293682023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293692023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293702023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293712023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293722023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293732023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293742023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
293752023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
293762023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293772023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293782023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293792023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293802023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293812023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293822023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293832023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293842023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293852023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293862023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293872023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293882023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293892023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293902023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293912023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293922023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293932023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293942023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293952023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293962023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293972023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293982023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
293992023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294002023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294012023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294022023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294032023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294042023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294052023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294062023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294072023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294082023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294092023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294102023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294112023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294122023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294132023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294142023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294152023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294162023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294172023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294182023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294192023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294202023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294212023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294222023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294232023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294242023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294252023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294262023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294272023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294282023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294292023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294302023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294312023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294322023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294332023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294342023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294352023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294362023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294372023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294382023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294392023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294402023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294412023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294422023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294432023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294442023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294452023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294462023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294472023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294482023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294492023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294502023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294512023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294522023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294532023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294542023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294552023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294562023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294572023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294582023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294592023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294602023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294612023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294622023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294632023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294642023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294652023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294662023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294672023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294682023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294692023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294702023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294712023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294722023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294732023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294742023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294752023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294762023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294772023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294782023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294792023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294802023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294812023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294822023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294832023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294842023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294852023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294862023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294872023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294882023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294892023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294902023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294912023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294922023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294932023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294942023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294952023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294962023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294972023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
294982023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
294992023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
295002023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295012023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295022023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295032023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295042023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295052023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295062023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295072023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295082023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295092023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295102023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295112023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295122023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295132023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295142023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295152023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295162023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295172023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295182023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295192023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295202023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295212023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
295222023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
295232023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295242023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295252023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295262023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295272023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295282023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295292023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295302023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295312023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295322023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295332023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295342023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295352023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295362023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295372023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295382023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295392023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295402023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295412023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295422023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295432023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295442023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295452023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295462023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295472023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295482023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295492023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295502023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295512023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295522023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295532023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295542023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295552023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295562023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295572023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295582023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295592023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295602023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295612023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295622023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295632023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295642023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295652023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295662023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295672023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295682023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295692023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295702023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295712023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295722023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295732023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295742023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295752023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295762023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295772023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295782023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295792023-03-10 22:22:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x2B720C5||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
295802023-03-10 22:22:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x2B7018F||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
295812023-03-10 22:22:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x2B70208||Logon Type: 2||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
295822023-03-10 22:22:00Microsoft-Windows-Security-Auditing4634LogoffAn account was logged off.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0x2B72247||Logon Type: 7||This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
295832023-03-10 22:22:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2B720C5||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
295842023-03-10 22:22:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2B72247| Linked Logon ID: 0x2B720C5| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
295852023-03-10 22:22:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 7| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2B720C5| Linked Logon ID: 0x2B72247| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Negotiat| Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
295862023-03-10 22:22:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0x378| Process Name: C:\Windows\System32\lsass.exe||Network Information:| Network Address: -| Port: -||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
295872023-03-10 22:22:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
295882023-03-10 22:22:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
295892023-03-10 22:22:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
295902023-03-10 22:22:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2B7018F||Privileges: SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
295912023-03-10 22:22:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: No||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2B70208| Linked Logon ID: 0x2B7018F| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
295922023-03-10 22:22:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 11| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon ID: 0x2B7018F| Linked Logon ID: 0x2B70208| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Workstation Name: DESKTOP-L9NRCO2| Source Network Address: 127.0.0.1| Source Port: 0||Detailed Authentication Information:| Logon Process: User32 | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
295932023-03-10 22:22:00Microsoft-Windows-Security-Auditing4648LogonA logon was attempted using explicit credentials.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Logon GUID: {00000000-0000-0000-0000-000000000000}||Account Whose Credentials Were Used:| Account Name: prashant.badadhe| Account Domain: MicrosoftAccount| Logon GUID: {00000000-0000-0000-0000-000000000000}||Target Server:| Target Server Name: localhost| Additional Information: localhost||Process Information:| Process ID: 0xd50| Process Name: C:\Windows\System32\svchost.exe||Network Information:| Network Address: 127.0.0.1| Port: 0||This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
295942023-03-10 22:22:00Microsoft-Windows-Security-Auditing4738User Account ManagementA user account was changed.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Target Account:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Changed Attributes:| SAM Account Name: -| Display Name: Prashant Badadhe| User Principal Name: -| Home Directory: -| Home Drive: -| Script Path: -| Profile Path: -| User Workstations: -| Password Last Set: -| Account Expires: -| Primary Group ID: -| AllowedToDelegateTo: -| Old UAC Value: -| New UAC Value: -| User Account Control: -| User Parameters: -| SID History: -| Logon Hours: -||Additional Information:| Privileges: -
295952023-03-10 22:22:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
295962023-03-10 22:22:00Microsoft-Windows-Security-Auditing5059Other System EventsKey migration operation.||Subject:| Security ID: LOCAL SERVICE| Account Name: LOCAL SERVICE| Account Domain: NT AUTHORITY| Logon ID: 0x3E5||Process Information:| Process ID: 10312| Process Creation Time: ‎2023‎-‎10‎-‎02T21:55:55.262728500Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: {4FFB625F-E2B5-4AFB-8576-2E8824433276}| Key Type: User key.||Additional Information:| Operation: Export of persistent cryptographic key.| Return Code: 0x0
295972023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
295982023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
295992023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296002023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296012023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296022023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296032023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
296042023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
296052023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
296062023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296072023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296082023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296092023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296102023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296112023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296122023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
296132023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296142023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296152023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296162023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296172023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296182023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296192023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296202023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296212023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296222023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296232023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296242023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296252023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296262023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296272023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296282023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296292023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296302023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296312023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296322023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296332023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296342023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296352023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296362023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296372023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296382023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296392023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296402023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296412023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296422023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296432023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296442023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296452023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296462023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296472023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296482023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296492023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296502023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296512023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296522023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296532023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296542023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296552023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296562023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296572023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296582023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296592023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296602023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296612023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296622023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296632023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296642023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296652023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296662023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296672023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296682023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296692023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296702023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296712023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296722023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296732023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296742023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296752023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296762023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296772023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296782023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296792023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296802023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296812023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296822023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296832023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296842023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296852023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296862023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296872023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296882023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296892023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296902023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296912023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296922023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296932023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296942023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296952023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296962023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296972023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296982023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
296992023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297002023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297012023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297022023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297032023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297042023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297052023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297062023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297072023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297082023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297092023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297102023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297112023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297122023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297132023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297142023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297152023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297162023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297172023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297182023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297192023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297202023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297212023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297222023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297232023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297242023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297252023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297262023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297272023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297282023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297292023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297302023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297312023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297322023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297332023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297342023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297352023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297362023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297372023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297382023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297392023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297402023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297412023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297422023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297432023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297442023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297452023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297462023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297472023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297482023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297492023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297502023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297512023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297522023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297532023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297542023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297552023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297562023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297572023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297582023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297592023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297602023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297612023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297622023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297632023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297642023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297652023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297662023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297672023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297682023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297692023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297702023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297712023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297722023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297732023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297742023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297752023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297762023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297772023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297782023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297792023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297802023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297812023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297822023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297832023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297842023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297852023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297862023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297872023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297882023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297892023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297902023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297912023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297922023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297932023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297942023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297952023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297962023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297972023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297982023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
297992023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298002023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298012023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298022023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298032023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298042023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298052023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298062023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298072023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298082023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298092023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298102023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298112023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298122023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298132023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298142023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298152023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298162023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298172023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298182023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298192023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298202023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298212023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298222023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298232023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298242023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298252023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298262023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298272023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298282023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298292023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298302023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298312023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298322023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298332023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298342023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298352023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298362023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298372023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298382023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298392023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298402023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298412023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298422023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298432023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298442023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298452023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298462023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298472023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298482023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298492023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298502023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298512023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298522023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298532023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298542023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298552023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298562023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298572023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298582023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298592023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298602023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298612023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298622023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298632023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298642023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298652023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298662023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298672023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298682023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298692023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298702023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298712023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298722023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298732023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298742023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298752023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298762023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298772023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298782023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298792023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298802023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298812023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298822023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298832023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298842023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298852023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298862023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298872023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298882023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298892023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298902023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298912023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298922023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298932023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298942023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298952023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298962023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298972023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298982023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
298992023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299002023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299012023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299022023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299032023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299042023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299052023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299062023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
299072023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
299082023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299092023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299102023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299112023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299122023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299132023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299142023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299152023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299162023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299172023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299182023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299192023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
299202023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
299212023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
299222023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
299232023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
299242023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
299252023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
299262023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
299272023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
299282023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
299292023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
299302023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
299312023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
299322023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
299332023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
299342023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
299352023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
299362023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
299372023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
299382023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
299392023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
299402023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
299412023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
299422023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
299432023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299442023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299452023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299462023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299472023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299482023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299492023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299502023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299512023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299522023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299532023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299542023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299552023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299562023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299572023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299582023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299592023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299602023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299612023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299622023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299632023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299642023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299652023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299662023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299672023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299682023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299692023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299702023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299712023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299722023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299732023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299742023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299752023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299762023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299772023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299782023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299792023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299802023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299812023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299822023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299832023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299842023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299852023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299862023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299872023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299882023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299892023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299902023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299912023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299922023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299932023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299942023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299952023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299962023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299972023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299982023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
299992023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300002023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300012023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300022023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300032023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300042023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
300052023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300062023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300072023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300082023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300092023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300102023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5780| Process Name: C:\Windows\System32\taskhostw.exe
300112023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5780| Process Name: C:\Windows\System32\taskhostw.exe
300122023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5780| Process Name: C:\Windows\System32\taskhostw.exe
300132023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5780| Process Name: C:\Windows\System32\taskhostw.exe
300142023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5780| Process Name: C:\Windows\System32\taskhostw.exe
300152023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5780| Process Name: C:\Windows\System32\taskhostw.exe
300162023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5780| Process Name: C:\Windows\System32\taskhostw.exe
300172023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x5780| Process Name: C:\Windows\System32\taskhostw.exe
300182023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
300192023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_office.net| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
300202023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
300212023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
300222023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
300232023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
300242023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300252023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300262023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300272023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300282023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300292023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300302023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300312023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300322023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300332023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
300342023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
300352023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300362023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300372023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300382023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300392023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300402023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300412023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300422023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300432023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300442023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300452023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300462023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300472023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300482023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300492023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300502023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300512023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300522023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300532023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300542023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300552023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300562023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300572023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300582023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300592023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300602023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300612023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300622023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300632023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300642023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300652023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300662023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300672023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300682023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300692023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300702023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300712023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300722023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300732023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300742023-03-10 22:22:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x4254| Process Name: C:\Windows\System32\LogonUI.exe
300752023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300762023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300772023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300782023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300792023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300802023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300812023-03-10 22:22:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300822023-03-10 22:22:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
300832023-03-10 22:22:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
300842023-03-10 19:18:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
300852023-03-10 19:18:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
300862023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300872023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300882023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300892023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300902023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300912023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300922023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
300932023-03-10 19:18:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
300942023-03-10 19:18:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
300952023-03-10 19:18:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
300962023-03-10 19:18:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
300972023-03-10 19:18:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
300982023-03-10 19:18:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Guest| Account Name: Guest| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
300992023-03-10 19:18:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\DefaultAccount| Account Name: DefaultAccount| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
301002023-03-10 19:18:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\Administrator| Account Name: Administrator| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x69a0| Process Name: C:\Windows\System32\taskhostw.exe
301012023-03-10 19:18:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
301022023-03-10 19:18:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
301032023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301042023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301052023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301062023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301072023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301082023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301092023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301102023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301112023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301122023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301132023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301142023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301152023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301162023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301172023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301182023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301192023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301202023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301212023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301222023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301232023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301242023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301252023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301262023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301272023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301282023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301292023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301302023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301312023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301322023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301332023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301342023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301352023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301362023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301372023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301382023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301392023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301402023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301412023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301422023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301432023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301442023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301452023-03-10 19:18:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
301462023-03-10 19:18:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
301472023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301482023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301492023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301502023-03-10 19:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301512023-03-10 19:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301522023-03-10 19:18:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
301532023-03-10 19:18:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
301542023-03-10 19:18:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
301552023-03-10 15:18:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
301562023-03-10 15:18:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
301572023-03-10 15:18:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
301582023-03-10 15:18:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
301592023-03-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301602023-03-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301612023-03-10 15:18:00Microsoft-Windows-Security-Auditing4798User Account ManagementA user's local group membership was enumerated.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||User:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2||Process Information:| Process ID: 0x4254| Process Name: C:\Windows\System32\LogonUI.exe
301622023-03-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301632023-03-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301642023-03-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301652023-03-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301662023-03-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301672023-03-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301682023-03-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301692023-03-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301702023-03-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301712023-03-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301722023-03-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301732023-03-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301742023-03-10 15:18:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301752023-03-10 15:18:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301762023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301772023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301782023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301792023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301802023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301812023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301822023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301832023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301842023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301852023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301862023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301872023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301882023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301892023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301902023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301912023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301922023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301932023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301942023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301952023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301962023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301972023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
301982023-03-10 15:17:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
301992023-03-10 15:17:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302002023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302012023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302022023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302032023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302042023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302052023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302062023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302072023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302082023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302092023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302102023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302112023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302122023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302132023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302142023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302152023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302162023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302172023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302182023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302192023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302202023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302212023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302222023-03-10 15:16:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302232023-03-10 15:16:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302242023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302252023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302262023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302272023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302282023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302292023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302302023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302312023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302322023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302332023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302342023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302352023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302362023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302372023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302382023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302392023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302402023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302412023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302422023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302432023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302442023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302452023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302462023-03-10 15:15:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302472023-03-10 15:15:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302482023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302492023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302502023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302512023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302522023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302532023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302542023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302552023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302562023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302572023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302582023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302592023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302602023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302612023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302622023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302632023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302642023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302652023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302662023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302672023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302682023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302692023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302702023-03-10 15:14:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302712023-03-10 15:14:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302722023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302732023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302742023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302752023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302762023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302772023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302782023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302792023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302802023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302812023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302822023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302832023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302842023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302852023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302862023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302872023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302882023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302892023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302902023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302912023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302922023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302932023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302942023-03-10 15:13:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302952023-03-10 15:13:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302962023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302972023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
302982023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
302992023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303002023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303012023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303022023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303032023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303042023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303052023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303062023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303072023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303082023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303092023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303102023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303112023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303122023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303132023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303142023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303152023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303162023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303172023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303182023-03-10 15:12:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303192023-03-10 15:12:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303202023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303212023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303222023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303232023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303242023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303252023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303262023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303272023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303282023-03-10 15:11:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
303292023-03-10 15:11:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
303302023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303312023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303322023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303332023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303342023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303352023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303362023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303372023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303382023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303392023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303402023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303412023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303422023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303432023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303442023-03-10 15:11:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303452023-03-10 15:11:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303462023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303472023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303482023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303492023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303502023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303512023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303522023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303532023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303542023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303552023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303562023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303572023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303582023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303592023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303602023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303612023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303622023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303632023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303642023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303652023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303662023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303672023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303682023-03-10 15:10:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303692023-03-10 15:10:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303702023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303712023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303722023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303732023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303742023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303752023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303762023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303772023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303782023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303792023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303802023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303812023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303822023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303832023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303842023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303852023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303862023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
303872023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
303882023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
303892023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
303902023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
303912023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
303922023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
303932023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
303942023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
303952023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
303962023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
303972023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
303982023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
303992023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304002023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304012023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304022023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304032023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304042023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304052023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304062023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304072023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304082023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304092023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304102023-03-10 15:09:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
304112023-03-10 15:09:00Microsoft-Windows-Security-Auditing4672Special LogonSpecial privileges assigned to new logon.||Subject:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7||Privileges: SeAssignPrimaryTokenPrivilege| SeTcbPrivilege| SeSecurityPrivilege| SeTakeOwnershipPrivilege| SeLoadDriverPrivilege| SeBackupPrivilege| SeRestorePrivilege| SeDebugPrivilege| SeAuditPrivilege| SeSystemEnvironmentPrivilege| SeImpersonatePrivilege| SeDelegateSessionUserImpersonatePrivilege
304122023-03-10 15:09:00Microsoft-Windows-Security-Auditing4624LogonAn account was successfully logged on.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||Logon Information:| Logon Type: 5| Restricted Admin Mode: -| Virtual Account: No| Elevated Token: Yes||Impersonation Level: Impersonation||New Logon:| Security ID: SYSTEM| Account Name: SYSTEM| Account Domain: NT AUTHORITY| Logon ID: 0x3E7| Linked Logon ID: 0x0| Network Account Name: -| Network Account Domain: -| Logon GUID: {00000000-0000-0000-0000-000000000000}||Process Information:| Process ID: 0x360| Process Name: C:\Windows\System32\services.exe||Network Information:| Workstation Name: -| Source Network Address: -| Source Port: -||Detailed Authentication Information:| Logon Process: Advapi | Authentication Package: Negotiate| Transited Services: -| Package Name (NTLM only): -| Key Length: 0||This event is generated when a logon session is created. It is generated on the computer that was accessed.||The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.||The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).||The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.||The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.||The impersonation level field indicates the extent to which a process in the logon session can impersonate.||The authentication information fields provide detailed information about this specific logon request.| - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.| - Transited services indicate which intermediate services have participated in this logon request.| - Package name indicates which sub-protocol was used among the NTLM protocols.| - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
304132023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304142023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304152023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304162023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304172023-03-10 15:09:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304182023-03-10 15:09:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304192023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304202023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304212023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304222023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304232023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304242023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304252023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304262023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304272023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304282023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304292023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304302023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304312023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304322023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304332023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304342023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304352023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304362023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304372023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304382023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304392023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304402023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304412023-03-10 15:08:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304422023-03-10 15:08:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304432023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304442023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304452023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304462023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304472023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304482023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304492023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304502023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304512023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304522023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304532023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304542023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304552023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304562023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304572023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304582023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304592023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304602023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304612023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304622023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304632023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304642023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304652023-03-10 15:07:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304662023-03-10 15:07:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304672023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304682023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304692023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304702023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304712023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304722023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304732023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304742023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304752023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304762023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304772023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304782023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304792023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304802023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304812023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304822023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304832023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304842023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304852023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304862023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304872023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304882023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304892023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304902023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304912023-03-10 15:06:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304922023-03-10 15:06:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304932023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304942023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304952023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304962023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304972023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
304982023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
304992023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
305002023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
305012023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
305022023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
305032023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
305042023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
305052023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
305062023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
305072023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
305082023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
305092023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
305102023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
305112023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
305122023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
305132023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
305142023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
305152023-03-10 15:05:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
305162023-03-10 15:05:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
305172023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
305182023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
305192023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
305202023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
305212023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305222023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305232023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305242023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305252023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305262023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305272023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305282023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305292023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305302023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305312023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305322023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305332023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305342023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305352023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305362023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305372023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305382023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305392023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305402023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305412023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305422023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305432023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305442023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305452023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305462023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305472023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305482023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305492023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305502023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305512023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305522023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305532023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305542023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305552023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305562023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305572023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305582023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305592023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305602023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305612023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305622023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305632023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305642023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305652023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305662023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305672023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305682023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305692023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305702023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305712023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305722023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305732023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305742023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305752023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305762023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305772023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305782023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305792023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305802023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305812023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305822023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305832023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305842023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305852023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305862023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305872023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305882023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305892023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305902023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305912023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305922023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305932023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305942023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305952023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305962023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305972023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305982023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
305992023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306002023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306012023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306022023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306032023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306042023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306052023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306062023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306072023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306082023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306092023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306102023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306112023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306122023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306132023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306142023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306152023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306162023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306172023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306182023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306192023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306202023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306212023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306222023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306232023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306242023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306252023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306262023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306272023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306282023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306292023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306302023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306312023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306322023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306332023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306342023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306352023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306362023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306372023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306382023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306392023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306402023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306412023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306422023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306432023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306442023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306452023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306462023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306472023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306482023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306492023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306502023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306512023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306522023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306532023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306542023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306552023-03-10 15:04:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
306562023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306572023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306582023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306592023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306602023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306612023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306622023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306632023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306642023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306652023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306662023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306672023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306682023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306692023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306702023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306712023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306722023-03-10 15:04:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306732023-03-10 15:04:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306742023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306752023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306762023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306772023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306782023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306792023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306802023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306812023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306822023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306832023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306842023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306852023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306862023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306872023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306882023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306892023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306902023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306912023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306922023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306932023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306942023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306952023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306962023-03-10 15:03:00Microsoft-Windows-Security-Auditing5382User Account ManagementVault credentials were read.||Subject:| Security ID: SYSTEM| Account Name: DESKTOP-L9NRCO2$| Account Domain: WORKGROUP| Logon ID: 0x3E7||This event occurs when a user reads a stored vault credential.
306972023-03-10 15:03:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
306982023-03-10 15:03:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
306992023-03-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
307002023-03-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
307012023-03-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
307022023-03-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
307032023-03-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
307042023-03-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
307052023-03-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
307062023-03-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
307072023-03-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
307082023-03-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
307092023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307102023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307112023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307122023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307132023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307142023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307152023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307162023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307172023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307182023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307192023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307202023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307212023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307222023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307232023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307242023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307252023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307262023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307272023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307282023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307292023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307302023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307312023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307322023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307332023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307342023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307352023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307362023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307372023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307382023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307392023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307402023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307412023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307422023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307432023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307442023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307452023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307462023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307472023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307482023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307492023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307502023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307512023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307522023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307532023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307542023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307552023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307562023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307572023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307582023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307592023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307602023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307612023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307622023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307632023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307642023-03-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
307652023-03-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
307662023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307672023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307682023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307692023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307702023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307712023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307722023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307732023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307742023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307752023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307762023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307772023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307782023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307792023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307802023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307812023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307822023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307832023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307842023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307852023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307862023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307872023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307882023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307892023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307902023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307912023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307922023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307932023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307942023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307952023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307962023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307972023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307982023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
307992023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308002023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308012023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308022023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308032023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308042023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308052023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308062023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308072023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308082023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308092023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308102023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308112023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308122023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308132023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308142023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308152023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308162023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308172023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308182023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308192023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308202023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308212023-03-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
308222023-03-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
308232023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308242023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308252023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308262023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308272023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308282023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308292023-03-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: RSA| Key Name: TB_0_microsoft.com| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
308302023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308312023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308322023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308332023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308342023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308352023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308362023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308372023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308382023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308392023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308402023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308412023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308422023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308432023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308442023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308452023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308462023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308472023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308482023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308492023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308502023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308512023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308522023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308532023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308542023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308552023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308562023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308572023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308582023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308592023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308602023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308612023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308622023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308632023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308642023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Read Credential||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308652023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308662023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308672023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308682023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308692023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308702023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308712023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308722023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308732023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308742023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308752023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308762023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308772023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308782023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308792023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308802023-03-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
308812023-03-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
308822023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308832023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308842023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308852023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308862023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308872023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308882023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308892023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308902023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308912023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308922023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308932023-03-10 15:02:00Microsoft-Windows-Security-Auditing5061System IntegrityCryptographic operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: AES| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Cryptographic Operation:| Operation: Open Key.| Return Code: 0x0
308942023-03-10 15:02:00Microsoft-Windows-Security-Auditing5058Other System EventsKey file operation.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B||Process Information:| Process ID: 17600| Process Creation Time: ‎2023‎-‎10‎-‎02T21:56:27.394232600Z||Cryptographic Parameters:| Provider Name: Microsoft Software Key Storage Provider| Algorithm Name: UNKNOWN| Key Name: Key2WrapEncryptionKey| Key Type: User key.||Key File Operation Information:| File Path: C:\Users\prash\AppData\Roaming\Microsoft\Crypto\Keys\e84a0c1ba3ac1fd825e56d898e3e81f8_9dc41865-e958-4a52-ae28-5b33ea299b46| Operation: Read persisted key from file.| Return Code: 0x0
308952023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308962023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308972023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308982023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
308992023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309002023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309012023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309022023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309032023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309042023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309052023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309062023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309072023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309082023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309092023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309102023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309112023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309122023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309132023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309142023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309152023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309162023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309172023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309182023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309192023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.
309202023-03-10 15:02:00Microsoft-Windows-Security-Auditing5379User Account ManagementCredential Manager credentials were read.||Subject:| Security ID: DESKTOP-L9NRCO2\prash| Account Name: prash| Account Domain: DESKTOP-L9NRCO2| Logon ID: 0xCCC8B| Read Operation: Enumerate Credentials||This event occurs when a user performs a read operation on stored credentials in Credential Manager.